<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Louwrentius - Uncategorized</title><link href="https://louwrentius.com/" rel="alternate"/><link href="https://louwrentius.com/feeds/uncategorized.atom.xml" rel="self"/><id>https://louwrentius.com/</id><updated>2026-07-23T12:00:00+02:00</updated><entry><title>I think you might be fooling yourself with AI</title><link href="https://louwrentius.com/i-think-you-might-be-fooling-yourself-with-ai.html" rel="alternate"/><published>2026-07-23T12:00:00+02:00</published><updated>2026-07-23T12:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2026-07-23:/i-think-you-might-be-fooling-yourself-with-ai.html</id><summary type="html">&lt;p&gt;If you are enthusiastic about AI (LLMs), you may be fooling yourself. Do not consider this an insult, but a kind-hearted warning.&lt;/p&gt;
&lt;p&gt;Remember what &lt;a href="https://www.youtube.com/watch?v=TwKpj2ISQAc&amp;amp;t=234"&gt;Richard Feynman&lt;/a&gt; said:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;The first principle is that you must not fool yourself
and you are the easiest person to fool.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://calteches.library.caltech.edu/51/2/CargoCult.htm"&gt;source&lt;/a&gt; (&lt;a href="https://web.archive.org/web/20260718112249/https://calteches.library.caltech.edu/51/2/CargoCult.htm"&gt;backup&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;He made this …&lt;/p&gt;</summary><content type="html">&lt;p&gt;If you are enthusiastic about AI (LLMs), you may be fooling yourself. Do not consider this an insult, but a kind-hearted warning.&lt;/p&gt;
&lt;p&gt;Remember what &lt;a href="https://www.youtube.com/watch?v=TwKpj2ISQAc&amp;amp;t=234"&gt;Richard Feynman&lt;/a&gt; said:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;The first principle is that you must not fool yourself
and you are the easiest person to fool.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://calteches.library.caltech.edu/51/2/CargoCult.htm"&gt;source&lt;/a&gt; (&lt;a href="https://web.archive.org/web/20260718112249/https://calteches.library.caltech.edu/51/2/CargoCult.htm"&gt;backup&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;He made this statement as part of the Caltech's 1974 commencement address. In this speech he strongly advocated for proper scientific integrity.&lt;/p&gt;
&lt;p&gt;I feel it can be difficult to maintain proper 'scientific integrity' on a personal level as AI is a fast-moving target. The tools feel unreasonably capable, using an LLM makes you feel more &lt;em&gt;productive&lt;/em&gt; when writing code for instance.&lt;/p&gt;
&lt;p&gt;Yet as of today, there is no independent scientific evidence&lt;sup id="fnref:confirmation"&gt;&lt;a class="footnote-ref" href="#fn:confirmation"&gt;1&lt;/a&gt;&lt;/sup&gt; (that I'm aware of) that people or organizations are indeed more &lt;em&gt;productive&lt;sup id="fnref:productive"&gt;&lt;a class="footnote-ref" href="#fn:productive"&gt;2&lt;/a&gt;&lt;/sup&gt;&lt;/em&gt; when using AI. &lt;/p&gt;
&lt;h2&gt;Are you really more 'productive'?&lt;/h2&gt;
&lt;p&gt;Meanwhile, &lt;a href="https://arxiv.org/pdf/2507.09089"&gt;a study (late 2025)&lt;/a&gt; seems to report that although participating developers felt they completed tasks faster using AI, they where around 19% slower. &lt;/p&gt;
&lt;p&gt;Using AI may feel faster and more productive, but you might be fooling yourself. You can never go back in time and measure yourself doing the task without using AI tools and compare the results. &lt;/p&gt;
&lt;p&gt;There is a reason why (scientific) experiments are often &lt;a href="https://en.wikipedia.org/wiki/Blinded_experiment"&gt;blind or double-blind&lt;/a&gt;. We want prevent personal bias from influencing the outcomes skewing the results and making us believe things that aren't true. Not so easy to do on your own.&lt;/p&gt;
&lt;p&gt;This is why I'm not really swayed by personal testimonies and anecdotes about how AI makes people more productive. How they vibe coded some app they would otherwise not have built&lt;sup id="fnref:money"&gt;&lt;a class="footnote-ref" href="#fn:money"&gt;3&lt;/a&gt;&lt;/sup&gt;. &lt;/p&gt;
&lt;p&gt;Do not be fooled by the mass layoffs 'due to AI' proving that AI is making people more productive. Sam Altman himself called many of these layoffs 'AI washing'. These are regular layoffs after a period of over-hiring and now the market corrects itself. Because aside from AI-related businesses, it seems that the economy isn't doing great.&lt;/p&gt;
&lt;p&gt;Furthermore, some of these layoffs seem to be specifically to &lt;a href="https://www.forbes.com/sites/karadennison/2026/06/17/companies-are-firing-workers-to-fund-ai-that-isnt-working-yet/"&gt;free up money to buy AI resources&lt;/a&gt;. Management by fear of being left behind. Firing people to get money to pay for unproven technology that may never be capable to replace the people being fired.&lt;/p&gt;
&lt;h2&gt;AI is unsustainable&lt;/h2&gt;
&lt;p&gt;Even if you still think AI is really making you more 'productive', enjoy it while it lasts.&lt;/p&gt;
&lt;p&gt;According to &lt;a href="https://www.techspot.com/news/112759-openai-anthropic-cant-afford-have-everyone-use-ai.html"&gt;this article&lt;/a&gt; ChatGPT starts losing money when you use your $200 subscription abouve 11%. If you'd use the full 100%, that same $200 subscription would allow you to use $14,000 worth in API pricing. That seems crazy to me.&lt;/p&gt;
&lt;p&gt;Whatever you think your productivity might be due to AI, I don't think it's worth the 'real' cost once the vendors stop heavily subsidizing AI usage. I really wonder how much usage AI would see if it would be just priced at cost. Would you feel as productive if the price would not be $200 but $2000 a month&lt;sup id="fnref:stress"&gt;&lt;a class="footnote-ref" href="#fn:stress"&gt;4&lt;/a&gt;&lt;/sup&gt;? A $200 subscription is not that big of a gamble, but any higher and it may feel less and less worth it. &lt;/p&gt;
&lt;h2&gt;Disclosure: my own bias against AI&lt;/h2&gt;
&lt;p&gt;Now it's time to be really open about my own bias. I'm an AI sceptic. I'm quite influenced by &lt;a href="https://www.wheresyoured.at"&gt;Ed Zitron's reporting&lt;/a&gt;. And I'm also standing by my own idea that AI will run out of money and &lt;a href="https://louwrentius.com/what-will-you-do-when-ai-runs-out-of-money-and-disappear.html"&gt;just be turned off&lt;/a&gt; due to the huge operational cost.&lt;/p&gt;
&lt;p&gt;It might feel unfathomable, unreasonable that this can happen. Maybe Google, AWS or Microsoft scoops up OpenAI or Antropic when they reach the end of the runway. But the economics won't change. Are they going to subsidize AI indefinitely?, to what end?&lt;/p&gt;
&lt;p&gt;I'm open to suggestions how this is going to play out. Close to a trillion dollars invested in AI. Where will the money come from to recuperate all these investments? If we disregard the AI (adjacent) companies, the USA economy seems to look &lt;a href="https://futurism.com/ai-bubble-economy-bleak"&gt;bleak&lt;/a&gt; (August 2025).&lt;/p&gt;
&lt;p&gt;I myself can't just close my eyes for all the externalities of AI. The energy usage in the context of climate change. The data centers disrupting poor communities. The large-scale theft of intellectual or copyrighted property. The enshitification and the enslopification of the internet. The mass hoarding of memory causing inflation.&lt;/p&gt;
&lt;p&gt;I'm not convinced the bad of AI is - or can be - compensated by the perceived good AI does. It's not possible to separate the tool itself from it's externalities. This is why I'm not using AI. I'm not using AI on moral, ethical grounds. &lt;/p&gt;
&lt;hr&gt;

&lt;p&gt;Hacker News discussion: &lt;a href="https://news.ycombinator.com/item?id=49021843"&gt;here&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Post Script&lt;/h2&gt;
&lt;p&gt;I found the comments on hacker news quite revealing. Most are very dismissive without engaging at all with the actual point of this article. &lt;/p&gt;
&lt;p&gt;It is true that the cited Metr study was followed up with a &lt;a href="https://metr.org/blog/2026-02-24-uplift-update/#wider-adoption-of-ai-has-made-it-more-difficult-to-measure-task-level-productivity"&gt;more recent study&lt;/a&gt; from 2026 that showed more productivity when using AI. The authors are also pointing out they paid way less and they had a problem where developers didn't want to code without AI.&lt;/p&gt;
&lt;p&gt;What was actually interesting about the initial study is the discrepancy between what developers thought and what they measured in terms of productivity. They were measurably fooling themselves.&lt;/p&gt;
&lt;p&gt;Furthermore, it seems that people are quick to respond and not actually read and comprehend what I wrote. There are two key points I'm making:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Your perception of productivity may be off / you may be fooling yourself&lt;/li&gt;
&lt;li&gt;In addition, I question and you may fool yourself thinking that the AI tool is worth the &lt;em&gt;unsubsidized&lt;/em&gt; cost in relation to the perceived productivity gain.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;At least I will try to be more explicit in my writing to get this point across. &lt;/p&gt;
&lt;p&gt;I must say I'm amazed at how fast people dismiss this blog post and make claims about AI productivity, without anyone providing anything else but personal anekdotes.&lt;/p&gt;
&lt;div class="footnote"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:confirmation"&gt;
&lt;p&gt;This may be due to my confirmation bias that I was unable to find any.&amp;#160;&lt;a class="footnote-backref" href="#fnref:confirmation" title="Jump back to footnote 1 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:productive"&gt;
&lt;p&gt;Whatever &lt;em&gt;productive&lt;/em&gt; really means in this context.&amp;#160;&lt;a class="footnote-backref" href="#fnref:productive" title="Jump back to footnote 2 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:money"&gt;
&lt;p&gt;how much value it delivers or how much revenue it creates is often not discussed. And don't fall for &lt;a href="https://en.wikipedia.org/wiki/Survivorship_bias"&gt;suvivorship bias&lt;/a&gt;.&amp;#160;&lt;a class="footnote-backref" href="#fnref:money" title="Jump back to footnote 3 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:stress"&gt;
&lt;p&gt;Or would you get stressed out and feel pressure to use the AI more to justify the expense and burn out?&amp;#160;&lt;a class="footnote-backref" href="#fnref:stress" title="Jump back to footnote 4 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content><category term="Uncategorized"/></entry><entry><title>The AI mirage or why I think the hype can't sustain itself</title><link href="https://louwrentius.com/the-ai-mirage-or-why-i-think-the-hype-cant-sustain-itself.html" rel="alternate"/><published>2026-06-30T12:00:00+02:00</published><updated>2026-06-30T12:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2026-06-30:/the-ai-mirage-or-why-i-think-the-hype-cant-sustain-itself.html</id><summary type="html">&lt;p&gt;If you zoom out enough, everything is a &lt;a href="https://en.wikipedia.org/wiki/Black_box"&gt;black box&lt;/a&gt; where we don't know about the inner workings, but we can learn about the black box by putting stuff in and observing the output. &lt;/p&gt;
&lt;p&gt;Let's pretend that a large language model or LLM is such a black box. If we …&lt;/p&gt;</summary><content type="html">&lt;p&gt;If you zoom out enough, everything is a &lt;a href="https://en.wikipedia.org/wiki/Black_box"&gt;black box&lt;/a&gt; where we don't know about the inner workings, but we can learn about the black box by putting stuff in and observing the output. &lt;/p&gt;
&lt;p&gt;Let's pretend that a large language model or LLM is such a black box. If we observe a LLM, we learn - amongst other things - that the output is 'correct' 99%&lt;sup id="fnref:argument"&gt;&lt;a class="footnote-ref" href="#fn:argument"&gt;1&lt;/a&gt;&lt;/sup&gt; of the time.&lt;/p&gt;
&lt;p&gt;This is a very fundamental and important observation. Computers are known for their correctness, for their reliability. We know that if we run a function with input A, we get output X, no matter what. Yes, packets can be lost, memory can go corrupt but those things go wrong in a predictable way. We check and retransmit packets, we use ECC memory. And data is formatted in such a way that we can detect lost packets or corrupted memory in the first place. Our entire world relies on it. &lt;/p&gt;
&lt;p&gt;Imagine that a system can't be trusted. That 1+1 isn't always 2. Only 99% of the time. How valuable can such a system be? That probably depends on the circumstances, but we know one thing for sure: we can't trust the output, it must be checked. It doesn't matter how, but it must be checked for correctness and that requires a person.&lt;/p&gt;
&lt;p&gt;We see it with self-driving cars. It's really impressive what is possible. But they aren't true self-driving&lt;sup id="fnref:waymo"&gt;&lt;a class="footnote-ref" href="#fn:waymo"&gt;2&lt;/a&gt;&lt;/sup&gt;. A person needs to be sitting at the wheel, keeping their attention focussed on traffic as if they would be driving themselves, so they can intervene when the AI makes an inevitable mistake.&lt;/p&gt;
&lt;p&gt;Although this post isn't about self-driving cars, we know that humans have a tenancy to get distracted and bored if we aren't actively engaged. We can argue that either we people keep driving ourselves, or we need 100% reliability, so we can remove the steering wheel and read a book while the car drives itself. Only 100% is good-enough, 99% doesn't cut it. What did we actually solve if I'm still required to 'drive' the car because of the 1% chance things go wrong?&lt;/p&gt;
&lt;p&gt;In the case of an LLM, how much time is saved by letting a person check the output of an LLM? Can that saved time justify the &lt;em&gt;actual&lt;/em&gt; operating cost of the LLM, as opposed to the &lt;em&gt;subsidized&lt;/em&gt; cost AI vendors are currently charging?&lt;/p&gt;
&lt;p&gt;In case of writing code, an LLM can probably create more functionality and features in a week a team of 100 engineers can validate in a year. So no matter what how fast the LLMs really are, the people are the bottleneck we can't circumvent.&lt;/p&gt;
&lt;p&gt;That is, if we care about correctness, about quality, about stability and so on. But if we don't, why do something in the first place, regardless of an LLM being involved or not?&lt;/p&gt;
&lt;p&gt;So this is why I think it's impossible for the AI hype to come through on the sky high promises their absurd valuations suggest. I'm not saying that AI may not be valuable&lt;sup id="fnref:ignore"&gt;&lt;a class="footnote-ref" href="#fn:ignore"&gt;3&lt;/a&gt;&lt;/sup&gt; but probably &lt;em&gt;orders of magnitude less valuable&lt;/em&gt; than people want us to believe. &lt;/p&gt;
&lt;p&gt;I admit, this isn't an original idea, people have voiced this idea in different, maybe &lt;a href="https://blog.miguelgrinberg.com/post/why-generative-ai-coding-tools-and-agents-do-not-work-for-me"&gt;more succinct ways&lt;/a&gt;. Yet I think it is worth repeating. &lt;/p&gt;
&lt;h3&gt;Update - but humans aren't accurate either!&lt;/h3&gt;
&lt;p&gt;Why replace people with something objectively worse and more unpredictable?
Humans check human output. Now humans check LLM output. Throughput is the same, but we fired a person and the remaining person is miserable due to the nature of the work.&lt;/p&gt;
&lt;p&gt;P.S. &lt;/p&gt;
&lt;p&gt;I also don't understand why organizations would make LLMs a very integral part of their processes, only to discover that models are changed and tweaked, resulting in wildly unpredictable and different output.&lt;/p&gt;
&lt;p&gt;Sometimes, when the light hits an LLM just right and you squint your eyes, it takes the shape of a crypto currency. At least that's what I see.&lt;/p&gt;
&lt;div class="footnote"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:argument"&gt;
&lt;p&gt;the number is based on nothing, in practice it's probably worse and the actual value is not important except to note that it's not 100%.&amp;#160;&lt;a class="footnote-backref" href="#fnref:argument" title="Jump back to footnote 1 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:waymo"&gt;
&lt;p&gt;don't be fooled by Waymo, it's still a limited system and operated remotely by people when needed.&amp;#160;&lt;a class="footnote-backref" href="#fnref:waymo" title="Jump back to footnote 2 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:ignore"&gt;
&lt;p&gt;I'm ignoring the energy 'waste', pollution, the IP theft, the copyright infringement, the AI-induced self-harm. On and on the list goes.&amp;#160;&lt;a class="footnote-backref" href="#fnref:ignore" title="Jump back to footnote 3 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content><category term="Uncategorized"/></entry><entry><title>I build a 10 inch mini rack from aluminium extrusions</title><link href="https://louwrentius.com/i-build-a-10-inch-mini-rack-from-aluminium-extrusions.html" rel="alternate"/><published>2026-06-20T12:00:00+02:00</published><updated>2026-06-20T12:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2026-06-20:/i-build-a-10-inch-mini-rack-from-aluminium-extrusions.html</id><summary type="html">&lt;p&gt;I built a 10-inch mini rack from aluminium extrusions and I had a lot of fun doing it. I want to share my build in this post.&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack01_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack01_l.webp" /&gt;&lt;/p&gt;
&lt;p&gt;In January of 2025, Jeff Geerling released a &lt;a href="https://www.youtube.com/watch?v=y1GCIwLm3is"&gt;video about 10-inch mini racks&lt;/a&gt;. I was absolutely oblivious to this new trend, and I …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I built a 10-inch mini rack from aluminium extrusions and I had a lot of fun doing it. I want to share my build in this post.&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack01_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack01_l.webp" /&gt;&lt;/p&gt;
&lt;p&gt;In January of 2025, Jeff Geerling released a &lt;a href="https://www.youtube.com/watch?v=y1GCIwLm3is"&gt;video about 10-inch mini racks&lt;/a&gt;. I was absolutely oblivious to this new trend, and I instantly knew that I wanted to build one for myself some day, although I didn't have a real use for one.&lt;/p&gt;
&lt;p&gt;That said, I've been working on a virtualization project recently and I've bought six &lt;a href="https://louwrentius.com/the-raspberry-pi-5-is-no-match-for-a-tini-mini-micro-pc.html"&gt;1L PC's&lt;/a&gt; (three for each simulated datacenter).&lt;/p&gt;
&lt;p&gt;Because these 1L PCs are small, they have huge external power bricks. As these mini PCs are also connected to two networks, they create a huge mess on my desk. Finally &lt;em&gt;a&lt;/em&gt; reason to build a mini rack, to tidy things up!&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack02_s.jpg)" src="https://louwrentius.com/static/images/rack/10inchrack02_l.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;There are a &lt;a href="https://github.com/geerlingguy/mini-rack#racks"&gt;few different brands of mini rack&lt;/a&gt; for sale, but I wanted to make one for myself. Prebuilt racks (kits) are not cheap for what they are so I wanted to try and see if I could build one myself for less money. Turns out you can buy 20mm aluminium extrusions and accompanying components to build your own rack.&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack04_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack04_l.webp" /&gt;
&lt;em&gt;(Aluminium extrusions have a standardized 'groove')&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Aluminium extrusions are bars with a groove on all four sides. These bars have a standard format and you can slide all kinds of equipment in there and lock it in place with set screws. It seems to be used a lot for home made 3D printers, &lt;a href="https://www.youtube.com/watch?v=-RaHk6ckrEI"&gt;CNC machines&lt;/a&gt; and whatnot. In the picture above a special corner piece is used to connect three bars together, fixed in place with set screws.&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack06_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack06_l.webp" /&gt;&lt;/p&gt;
&lt;p&gt;The L-brackets can be used to create T-sections within a frame to sturdy the structure and provide additional mounting points. In my rack, the middle post carries the back of the shelves holding the mini PCs.&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack07_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack07_l.webp" /&gt;&lt;/p&gt;
&lt;p&gt;These sliding cage nuts (M5) can be used to attach anything anywhere. In this example we used four of them to hold the side panels in place. These cage nuts can also be used for their intended purpose: mount 10 inch rack-mount equipment. &lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack05_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack05_l.webp" /&gt;&lt;/p&gt;
&lt;p&gt;In this picture below, some cage nuts are left that hold the side panel in place. Also notice in the upper left that I've used cage nuts to attach some black cable tie holders that in turn keep cables in place.&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack08_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack08_l.webp" /&gt;&lt;/p&gt;
&lt;h3&gt;The computer trays&lt;/h3&gt;
&lt;p&gt;I planned on ordering 10 inch 1U shelves and be done with it. Unfortunately these metal shelves are too expensive for my taste and would have cost more than the aluminium frame including components (I need 8 shelves).&lt;/p&gt;
&lt;p&gt;Many 10-inch rack builds - such as the ones featured by Jeff Geerling - use 3D-printed face plates to mount various kinds of equipment. Jeff showcased some of these models in separate videos. That said, I decided against using 3D printed shelves.&lt;/p&gt;
&lt;p&gt;First of all, I don't have a 3D printer and as useful as 3D printing can be, I feel that 3D printers often turn plastic into landfill. I'd probably feel differently if (more) sustainable materials would have been used&lt;sup id="fnref:argument"&gt;&lt;a class="footnote-ref" href="#fn:argument"&gt;1&lt;/a&gt;&lt;/sup&gt;. &lt;/p&gt;
&lt;p&gt;So instead, I chose to order cut-to-size aluminium sheets and I used the L-brackets to hold them in place.&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack09_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack09_l.webp" /&gt;&lt;/p&gt;
&lt;p&gt;The aluminium shelves turned out OK, but they are not ideal. The 1mm thick plates do bend slightly under the weight of the computers, although it's still fine. Aligning the four L-brackets on the same horizontal plane was a pain. Filing off the sharp corners of each plate was no fun, I should have ordered them with rounded corners.&lt;/p&gt;
&lt;p&gt;I think these aluminium plates create an open design that is better for keeping the machines cool. There are many 10-inch self 3D models available for these 1L PCs but they all create a tight collar around the front bezel of the computer, which looks amazing, but I don't think it's great for airflow. Regular metal shelves would also have been fine.&lt;/p&gt;
&lt;h3&gt;10 inch power distribution&lt;/h3&gt;
&lt;p&gt;As you can see below, the backside shows the internals of the case are a bit of a mess&lt;sup id="fnref:table"&gt;&lt;a class="footnote-ref" href="#fn:table"&gt;2&lt;/a&gt;&lt;/sup&gt;. The truth is that I've should made the rack at least 1U higher to accommodate the very lengthy cabling of the power bricks. All the cabling does fit, but it's not easy to make it clean looking and also give the power bricks - which lie at the bottom - some airflow. &lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack03_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack03_l.webp" /&gt;
&lt;em&gt;No price for cabling management and neatness, that's for sure&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I've used two 10-inch rack mount power distribution units from Brenenstuhl. They were cheap but they unfortunately didn't fit in a horizontal position. The PDUs are the only actual 10-inch rack-mount component in the entire build and the fact that they didn't fit felt ironic. &lt;/p&gt;
&lt;p&gt;The cause is simple: in a 19-inch or 10-inch rack, the square holes holding the cage nuts are 'flat sheets', so the power cable sticking out of the side of the PDU can flow behind those square holes. If you use the 20mm aluminum extrusions, there is a 20mm bar in the way. This is why I had to mount the PDUs vertically, which did work fine. At the top, the PDUs are kept in place with another L-bracket clamping the PDUs firm against the rail.&lt;/p&gt;
&lt;p&gt;The external power bricks of the 1L PCs' are a huge pain. Having six cords and external adapters was absolutely no option for me, I wanted a fully self-contained rack. If you ever build your own rack, try to use computers that have a power supply build-in.&lt;/p&gt;
&lt;p&gt;I wish I could power these 1L PCs with a 'power shelf'. In this case, a power supply with enough capacity to sustain these PCs at the required voltage and with the proper brand-correct power jack, &lt;a href="https://www.reddit.com/r/HomeServer/comments/1ry69to/3_elitedesk_mini_one_power_supply_homeserver_15/"&gt;maybe like this&lt;/a&gt;. &lt;/p&gt;
&lt;h3&gt;Cooling&lt;/h3&gt;
&lt;p&gt;All power sockets are in use by the six 1L PCs and the two network switches, so how are we going to power the two cooling fans&lt;sup id="fnref:fans"&gt;&lt;a class="footnote-ref" href="#fn:fans"&gt;3&lt;/a&gt;&lt;/sup&gt;?&lt;/p&gt;
&lt;p&gt;Fortunately there exist USB-to-fan-header cables. It feels dirty but it isn't. USB is only 5 volt but these adapters contain a boost converter that outputs 12 volt for the fans. The power draw of these fans (around 1W) is well below the threshold of 4.5W for a USB3 port.&lt;/p&gt;
&lt;p&gt;The open backside probably doesn't help with cooling and Ideally I'd fill in the gaps. Due the the irregular shapes, I feel it's too much effort. I do feel a proper airflow at the front of the 1L PCs, so I think it's 'certified good enough&lt;sup id="fnref:matt"&gt;&lt;a class="footnote-ref" href="#fn:matt"&gt;4&lt;/a&gt;&lt;/sup&gt;'.&lt;/p&gt;
&lt;h3&gt;Networking&lt;/h3&gt;
&lt;p&gt;The 1L PCs have two network connections, one to each switch. The 3Com switch at the top is 1 Gbit, the TRENDnet switch is 2.5 Gbit. I used the Conceptroning &lt;a href="https://www.conceptronic.net/conceptronic_en/abby12g-2-5g-ethernet-usb-3-0-adapter-wake-on-lan-compatible-with-nintendo-switch-110519907101"&gt;ABBY12G&lt;/a&gt; USB3-to-2.5Gbe adapter to connect the 1L PCs to the switch. &lt;/p&gt;
&lt;p&gt;The 2.5 Gigabit network is a backend network for live migration of virtual machines amongst other traffic. I'm able to achieve line-speed with both iperf3 and virtual machine migrations.&lt;/p&gt;
&lt;p&gt;&lt;img alt="![10 inch rack](https://louwrentius.com/static/images/rack/10inchrack10_s.webp)" src="https://louwrentius.com/static/images/rack/10inchrack10_l.webp" /&gt;
&lt;em&gt;The gigabit 3com switch is at least 26, maybe 27 years old!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The rack has become a bit crowded due to all this network connectivity, as seen on earlier pictures. It didn't help that I ordered short UTP cables that are quite stiff. &lt;/p&gt;
&lt;h3&gt;Panels&lt;/h3&gt;
&lt;p&gt;The side panels are sheets of anodized aluminium which look good, in my opinion.
I forgot to order panels for the top and bottom. Therefore, I decided to go with some wood panels instead of aluminium sheet metal. &lt;/p&gt;
&lt;p&gt;A local shop offers scrap wood for peanuts and also cuts it to size for a 'few peanuts more'. Very handy if you don't have the right equipment to make straight, clean cuts of wood. &lt;/p&gt;
&lt;p&gt;Although not pictured, the bottom panel is kept in place with screws locking into cage nuts. These screws also hold the rubber feet in place.&lt;/p&gt;
&lt;h3&gt;Problems&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;A lack of access to the VGA/DP ports&lt;/strong&gt;: &lt;/p&gt;
&lt;p&gt;If I lock myself out of a machine, I need to remove one or more fans and connect a VGA/DP cable to the back of the affected machine. This also means moving a lot of UTP cables to the side. I can attach a keyboard to the front but attaching a monitor is thus a real pain. In more regular rack builds, you can add 'keystones' that extend ports to a panel on the outside of the case, where you can connect to an interface without any issue. &lt;/p&gt;
&lt;h3&gt;Cost&lt;/h3&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th style="text-align: right;"&gt;Total&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Aluminium sheets&lt;/td&gt;
&lt;td style="text-align: right;"&gt;82.95 €&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aluminium extrusions&lt;/td&gt;
&lt;td style="text-align: right;"&gt;26.22 €&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rack mount small items&lt;/td&gt;
&lt;td style="text-align: right;"&gt;79.96  €&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;wood&lt;/td&gt;
&lt;td style="text-align: right;"&gt;7 €&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;shipping costs (over all orders)&lt;/td&gt;
&lt;td style="text-align: right;"&gt;20 €&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;USB to 2x 4-pin fan header&lt;/td&gt;
&lt;td style="text-align: right;"&gt;12 €&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10 Inch PDU 2x&lt;/td&gt;
&lt;td style="text-align: right;"&gt;43 €&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network cables&lt;/td&gt;
&lt;td style="text-align: right;"&gt;42.15 €&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total Price&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: right;"&gt;&lt;strong&gt;313.28 €&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;All prices include 21% Dutch sales tax. The total price excludes the two Noctua fans, which would probably add another 40 euros.&lt;/p&gt;
&lt;p&gt;The price is a bit inflated because I overbought small items for rack building. If I opted for wood paneling instead of aluminum panels, that would probably also cut the paneling cost in half.&lt;/p&gt;
&lt;h2&gt;How I use this mini rack&lt;/h2&gt;
&lt;p&gt;The mini PCs are running Debian and they all act as virtualization hosts, using KVM. The gigabit ports are used for the management and provisioning network (PXE+TFTP+iPXE+HTTP). The 2.5Gbit network is used for virtual machine migration and a VXLAN network that encapsulates all the different virtual machine networks.&lt;/p&gt;
&lt;p&gt;By default, this rack is off. When I want to use it, I turn on a Zigbee power adapter and after a delay, wake-on-lan packets are sent to all six machines to power them on. &lt;/p&gt;
&lt;h2&gt;Power consumption&lt;/h2&gt;
&lt;p&gt;The two switches, two fans and six 1L PCs together use around ~90W idle.&lt;/p&gt;
&lt;h3&gt;Evaluation&lt;/h3&gt;
&lt;p&gt;I'm quite happy with this build. Cost was acceptable, I think it looks decent enough and it really cleans up my desk. Although cable management is clearly not my strong suit, I feel it's an overall improvement. Maybe a few handles for carrying would be a nice future addition, but for now this rack is finished.&lt;/p&gt;
&lt;p&gt;Did I save any money? I'm not so sure.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://news.ycombinator.com/item?id=48702917"&gt;Hacker News discussion&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Acknowledgements&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Jeff Geerling for introducing me to &lt;a href="https://github.com/geerlingguy/mini-rack"&gt;10 inch racks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://loganmarchione.com/2025/09/homelab-10-mini-rack-v2/"&gt;This build&lt;/a&gt; by Logan Marchione inspired me to further look into aluminium extrusions&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="footnote"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:argument"&gt;
&lt;p&gt;If you feel differently about 3D printing that's OK. I'm not looking for a discussion or argument about the topic, I'm only stating my motivations.&amp;#160;&lt;a class="footnote-backref" href="#fnref:argument" title="Jump back to footnote 1 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:table"&gt;
&lt;p&gt;it's so, so much cleaner than the mess of wires on my desk. I'm already happy with this improvement.&amp;#160;&lt;a class="footnote-backref" href="#fnref:table" title="Jump back to footnote 2 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:fans"&gt;
&lt;p&gt;The fans I used are of different size and type, in part because it's what I had lying around.&amp;#160;&lt;a class="footnote-backref" href="#fnref:fans" title="Jump back to footnote 3 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:matt"&gt;
&lt;p&gt;https://www.youtube.com/SuperfastMatt&amp;#160;&lt;a class="footnote-backref" href="#fnref:matt" title="Jump back to footnote 4 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content><category term="Uncategorized"/></entry><entry><title>I think Rutger Bregman &amp; The School for Moral Ambition are full of shit</title><link href="https://louwrentius.com/i-think-rutger-bregman-the-school-for-moral-ambition-are-full-of-shit.html" rel="alternate"/><published>2026-06-08T12:00:00+02:00</published><updated>2026-06-08T12:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2026-06-08:/i-think-rutger-bregman-the-school-for-moral-ambition-are-full-of-shit.html</id><summary type="html">&lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: I'm just a random person on the internet and this article is my personal opinion. This article was written without AI.&lt;/p&gt;
&lt;hr&gt;

&lt;p&gt;The first time I heard from Rutger Bregman was due to his remarks at Davos about &lt;a href="https://www.theguardian.com/business/2019/jan/30/historian-berates-billionaires-at-davos-over-tax-avoidance"&gt;taxing the billionaires&lt;/a&gt;. His speech went viral and I was rooting for …&lt;/p&gt;</summary><content type="html">&lt;p&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;: I'm just a random person on the internet and this article is my personal opinion. This article was written without AI.&lt;/p&gt;
&lt;hr&gt;

&lt;p&gt;The first time I heard from Rutger Bregman was due to his remarks at Davos about &lt;a href="https://www.theguardian.com/business/2019/jan/30/historian-berates-billionaires-at-davos-over-tax-avoidance"&gt;taxing the billionaires&lt;/a&gt;. His speech went viral and I was rooting for him. Later on he got to &lt;a href="https://www.youtube.com/watch?v=6_nFI2Zb7qE&amp;amp;t=1s"&gt;troll Tucker Carlson&lt;/a&gt; about Carlson being a millionaire working for billionaires. Absolutely fantastic.&lt;/p&gt;
&lt;p&gt;A few &lt;a href="https://rutgerbregman.com/books"&gt;books&lt;/a&gt; in, Bregman started the &lt;a href="https://www.moralambition.org"&gt;School for Moral ambition&lt;/a&gt; in 2024. Although he is a co-founder, he seems to be face of this non-profit organisation, doing a lot of high-visibility interviews and he's the author of the book "Moral Ambition".&lt;/p&gt;
&lt;p&gt;The idea behind the School for Moral Ambition (SMA) is quite simple: use your talent to address the world's biggest problems. To paraphrase: "don't become a consultant at McKinsey but do something more valuable and worthwhile with your talent". The argument is similar to what Steve Jobs said to John Sculley: &lt;em&gt;"Do you want to sell sugar water for the rest of your life, or come with me and change the world?"&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;It sounds all very noble, but I've become a skeptic for multiple reasons.&lt;/p&gt;
&lt;p&gt;Bregman rubbed me the wrong way in the last podcast episode of the "&lt;a href="https://decorrespondent.nl/collectie/de-rudi-freddie-show"&gt;De Rudi &amp;amp; Freddie Show&lt;/a&gt;" in 2024. He confronted co-host and award-winning investigative journalist &lt;a href="https://nl.wikipedia.org/wiki/Jesse_Frederik"&gt;Jesse Frederik&lt;/a&gt; and openly questioned if his work really made a difference. Bregman implicated that Frederik could do other things that would be much more effective and be more impactful than his investigative journalism (I'm paraphrasing here).&lt;/p&gt;
&lt;p&gt;I'm absolutely comfortable with questions like these, although it can feel confrontational. Yet I really felt it came from a somewhat righteous and smug moral superiority. I felt this way because I haven't seen any evidence&lt;sup id="fnref:objective"&gt;&lt;a class="footnote-ref" href="#fn:objective"&gt;1&lt;/a&gt;&lt;/sup&gt; that SMA has done anything of substance that warrants all the money involved. &lt;/p&gt;
&lt;h2&gt;Bregman drank the AI cool-aid&lt;/h2&gt;
&lt;p&gt;Now I already learned that Bregman was really enamoured with AI, and I'm absolutely not, for the usual reasons. That said, fast forwarding to today, I truly believe he has lost the plot, and this recent video (June 2026) is evidence of it.&lt;/p&gt;
&lt;iframe width="560" height="315" src="https://www.youtube-nocookie.com/embed/KpTZbq-eV38?si=a_JrEoLYkIHAppYZ" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen&gt;&lt;/iframe&gt;

&lt;p&gt;He is comparing skepticism of artificial intelligence with climate change denial or climate skepticism. He sees AI as a tool that is beneficiary, just not in the hands of billionaires but in the hands of governments (as I understand it). He believes that AI will create an utopia where people can actually work less hours as &lt;a href="https://www.npr.org/2015/08/13/432122637/keynes-predicted-we-would-be-working-15-hour-weeks-why-was-he-so-wrong"&gt;Keynes 'wrongfully' predicted&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Unfortunately for Bregman, as far as I can tell, there is no (scientific) evidence that AI is actually capable of having such a huge impact. Meanwhile compare this to the mountains of evidence for human-caused climate change, it would be a different story. I would expect a different argument from a former journalist. To reiterate: the case for climate change is rooted in a vast body of scientific research. The case for AI creating a 15-hour work week seems mostly backed by wishfull thinking.&lt;/p&gt;
&lt;p&gt;I feel that Bregman isn't really aware of his own biases, fuelled by his own personal experience using AI. He paints all the AI critics as &lt;a href="https://www.bloodinthemachine.com"&gt;'luddites'&lt;/a&gt;&lt;sup id="fnref:brian"&gt;&lt;a class="footnote-ref" href="#fn:brian"&gt;2&lt;/a&gt;&lt;/sup&gt; and that AI-skeptics are on the wrong side of history, just as the climate deniers are. Comparing AI skeptics to climate change skeptics feels like a cheap rhetoric trick that doesn't do justice to the criticism and skepsis surrounding AI.&lt;/p&gt;
&lt;p&gt;Bregman also believes that stopping AI or 'shutting it down' doesn't make sense. Because if we shut AI down in our countries, other countries or regimes will build AI and get an advantage over us (he shows China as an example). The age old "&lt;em&gt;if we don't, somebody else will&lt;/em&gt;", that has excused bad behaviour for all of eternity. &lt;/p&gt;
&lt;p&gt;The reality is that voters and the larger public never had any say how this AI technology is deployed. That we take into account the impact on communities, people, the use of energy and other resources. We never had any say in this. The entire AI-push seems anti-social, anti-democracy.&lt;/p&gt;
&lt;p&gt;Yes, the companies now pushing AI upon us are so huge and valued so high they are dwarfing the GDP of entire nations within Europe as Bregman suggests. Yet, I think there is strong evidence these numbers are not real. I sense such a lack of critical thinking and healthy skepticism about his own claims. He is dismissing the work of people like &lt;a href="https://www.wheresyoured.at"&gt;Ed Zitron&lt;/a&gt; who has unearthed a ton of evidence that AI doesn't deliver (or not nearly as much as is widely claimed) and there's a bubble that may collapse at some point. As I see it, Bregman only has a well-produced narative, but nothing more: it seems pure rhetoric.&lt;/p&gt;
&lt;p&gt;And then I learned something about SMA that made me really disappointed. &lt;/p&gt;
&lt;h2&gt;The School for Moral Ambition took money from Bill Gates&lt;/h2&gt;
&lt;p&gt;Bregman has been quite positive about Bill Gates contributions to society, mainly pointing at his work on fighting malaria. Unfortunately, it seems that Bregman has not done his due diligence about Bill Gates and his foundation. &lt;/p&gt;
&lt;p&gt;Fortunately, &lt;a href="https://about.me/tim_schwab"&gt;Tim Schwab&lt;/a&gt; - an investigative journalist - has investigated the Bill Gates foundation and the result has been documented in the book "The Bill Gates Problem: Reckoning with the Myth of the Good Billionaire". In this book, Schwab has demonstrated how problematic Bill Gates and his foundation really is. Remember that Bill Gates had deep ties to Jeffrey Epstein, which was cited by his ex-wife as a &lt;a href="https://www.bbc.com/news/articles/cr4kyk9nv5lo"&gt;reason to file for divorce&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Tim Schwab &lt;a href="https://timschwab.substack.com/p/he-built-a-brand-criticizing-billionaires"&gt;had contact with Bregman about this&lt;/a&gt; and I think it doesn't look good for Bregman. It's really bad for a former journalist to cite a source as evidence for Bill Gates good work that has financial ties to Gates. Schwab repeatedly tried to contact Bregman about this, but got the statement through Bregman's agent Anne Strunk: &lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;“He’s not a fan of your style of journalism, which seems grounded in bad faith instead of curiosity,” Strunk noted in an email.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When Schwab wrote his article in 2025, it wasn't known that Bregman and his School for Moral Ambition was funded in part by Bill Gates, Schwab discovered this by accident. (It's now disclosed on the website at the bottom).&lt;/p&gt;
&lt;p&gt;&lt;img alt="bill gates funds the school for Moral ambition" src="https://louwrentius.com/static/images/sma/website01.png" /&gt;&lt;/p&gt;
&lt;p&gt;Now for the life of me, I can't fathom boasting about &lt;em&gt;moral ambition&lt;/em&gt; and accepting money from Bill Gates. I just can't. And they &lt;em&gt;know it looks bad&lt;/em&gt; because if an organisation omits (at first) mentioning receiving funding from Bill Gates, you know &lt;em&gt;they know&lt;/em&gt; how bad that looks. Lying by omission.&lt;/p&gt;
&lt;p&gt;If SMA had any actual moral ambition, I think it would have been a cooperative. (Now it's just a typical hierarchical and opaque organisational structure with the 'owners' including Bregman, at the top.) I would expect that this organisation would also be extremely transparent where the money is spent on exactly. The &lt;a href="https://files.moralambition.org/SMA_2025_Impact_Report.pdf"&gt;impact report&lt;/a&gt; didn't really clarify anything for me. It's all testimonials, stories and anecdotes.&lt;/p&gt;
&lt;h2&gt;It gets so much worse&lt;/h2&gt;
&lt;p&gt;My jaw dropped when I read &lt;a href="https://www.counterpunch.org/2025/05/18/how-elites-rebrand-power-as-virtue/"&gt;this article&lt;/a&gt; by Anita Naidu. I learned that Dutch journalist Marieke Kuypers &lt;a href="https://bsky.app/profile/marieke.bsky.social/post/3lp4mbsaxas2k"&gt;discovered&lt;/a&gt; that the USA branch of SME runs out of the offices of &lt;a href="https://louwrentius.com/cryptocurrencies-are-detrimental-to-society.html"&gt;crypto&lt;/a&gt; billionaire Mike Novogratz and that Novograt's sister sits on the SMA's board. Mike Novogratz donated a milion dollars to Trump.&lt;/p&gt;
&lt;p&gt;At this point, I think that both Bregman and SME are &lt;em&gt;absolutely unredeemable&lt;/em&gt;.&lt;/p&gt;
&lt;h2&gt;Accusations of racism and elitism&lt;/h2&gt;
&lt;p&gt;In interviews I've noticed that Bregman talks a lot about 'talented' people. For him, talented people are highly educated people. To get a fellowship with SMA, there are all kinds of criteria a candidate needs to hit and one of them is academic credentials, work experience and so on.&lt;/p&gt;
&lt;p&gt;A picture does arise of a very elitist, and also tightly controlled organisation where the founders determine - based on criteria they pulled out of thin air - if you are a good candidate or not. And they alone decide what is moral, which topics should be spend time and effort on. &lt;/p&gt;
&lt;p&gt;This is what Anita Naidu articulates in an &lt;a href="https://www.counterpunch.org/2025/05/18/how-elites-rebrand-power-as-virtue/"&gt;article from 2025&lt;/a&gt; where she states:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Let’s be clear about who it’s built for. SMA isn’t for people organizing at the grassroots, risking safety to confront systems of oppression. It’s for the already credentialed: Ivy League grads, McKinsey consultants, social entrepreneurs. People groomed to lead—just not to surrender power. The School doesn’t ask them to reckon with injustice. It teaches them how to perform reckoning without threatening their position.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;She continues later on:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Instead of interrogating capitalism, colonialism, or white supremacy, SMA asks: how can we make these systems feel more ethical? How can we reframe domination as duty? Structural violence becomes a backdrop for personal growth. Justice becomes self-improvement. Revolution becomes résumé fodder.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Meanwhile, Payal Arora wrote a &lt;a href="https://payalarora.stck.me/post/50?fbclid=IwAR2YhcBWZ5HNcNcB5DOM7GpvGx-F2r4nN1ftwTQgC-P4klGqycQ7HpaLN90"&gt;critical piece&lt;/a&gt; on Bregmans &lt;a href="https://www.theguardian.com/books/2020/may/09/the-real-lord-of-the-flies-what-happened-when-six-boys-were-shipwrecked-for-15-months?fbclid=IwAR34uy7xD4QfBrDgZ-FORIgaAw_4Nisk2jQXxzy76QJMsJkGM9_H00Phjbc"&gt;article&lt;/a&gt; (an adapted excerpt from his book 'Humankind' ) written in 2020. She critisizes Bregman for simplifying the story, leaving out important context about colonialism and racism, showing that the story is actually a counter-example to his hypothesis that people are good by nature&lt;sup id="fnref:counter"&gt;&lt;a class="footnote-ref" href="#fn:counter"&gt;3&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;According to Payal in &lt;a href="https://payalarora.com/2020/06/17/twitter-war-with-rutger-bregman/"&gt;this article&lt;/a&gt;, because of her criticism, she got into a 'twitter war' with Bregman about her criticism. &lt;/p&gt;
&lt;p&gt;I also found a &lt;a href="https://timschwab.substack.com/p/racism-rihanna-and-rutger-bregman"&gt;critical article&lt;/a&gt; and a &lt;a href="https://timschwab.substack.com/p/rutger-bregman-apologizes-for-racist"&gt;follow up article&lt;/a&gt; from (yet again) Tim Schwab about how Bregman handled the uncovering and critique on hist past racist remarks about Rihanna.&lt;/p&gt;
&lt;h2&gt;Closing words&lt;/h2&gt;
&lt;p&gt;At this point I can only ask the reader not to get involved with the School for Moral Ambition as I think SME isn't moral at all. I believe there is nothing of substance to SME and I don't see anything tangible this organisation has achieved with the money spent. &lt;/p&gt;
&lt;hr&gt;

&lt;p&gt;&lt;em&gt;Disclosure&lt;/em&gt;: I have no affiliations with tobacco producers or processors, I'm not a wealthy person trying to evade taxation and I'm also not in any way affiliated with food or meat production. In short, SMA isn't working on anything that would affect me personally in a negative way.&lt;/p&gt;
&lt;div class="footnote"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:objective"&gt;
&lt;p&gt;Objectively verified by independent trusted third-parties&amp;#160;&lt;a class="footnote-backref" href="#fnref:objective" title="Jump back to footnote 1 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:brian"&gt;
&lt;p&gt;The luddite story was &lt;a href="https://www.bloodinthemachine.com"&gt;never about&lt;/a&gt; the technology itself, but the actual social context and impact, as is with AI.&amp;#160;&lt;a class="footnote-backref" href="#fnref:brian" title="Jump back to footnote 2 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:counter"&gt;
&lt;p&gt;not to say that this proves if people are good by nature or not, just that the story doesn't support Bregmans narative.&amp;#160;&lt;a class="footnote-backref" href="#fnref:counter" title="Jump back to footnote 3 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content><category term="Uncategorized"/></entry><entry><title>I resurrected my Dutch movie review site from 2003</title><link href="https://louwrentius.com/i-resurrected-my-dutch-movie-review-site-from-2003.html" rel="alternate"/><published>2022-06-09T12:00:00+02:00</published><updated>2022-06-09T12:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2022-06-09:/i-resurrected-my-dutch-movie-review-site-from-2003.html</id><summary type="html">&lt;h2&gt;Introduction&lt;/h2&gt;
&lt;p&gt;Between 2003 and 2006, I ran a &lt;em&gt;Dutch&lt;/em&gt; movie review site called &lt;a href="https://moevie.nl"&gt;moevie.nl&lt;/a&gt;.&lt;sup id="fnref:name"&gt;&lt;a class="footnote-ref" href="#fn:name"&gt;1&lt;/a&gt;&lt;/sup&gt;
I built the site and wrote the reviews. It never made any money. It cost me money to host, and it cost me a lot of time writing reviews, but I remember enjoying writing …&lt;/p&gt;</summary><content type="html">&lt;h2&gt;Introduction&lt;/h2&gt;
&lt;p&gt;Between 2003 and 2006, I ran a &lt;em&gt;Dutch&lt;/em&gt; movie review site called &lt;a href="https://moevie.nl"&gt;moevie.nl&lt;/a&gt;.&lt;sup id="fnref:name"&gt;&lt;a class="footnote-ref" href="#fn:name"&gt;1&lt;/a&gt;&lt;/sup&gt;
I built the site and wrote the reviews. It never made any money. It cost me money to host, and it cost me a lot of time writing reviews, but I remember enjoying writing reviews about films I liked.&lt;/p&gt;
&lt;p&gt;The gimmick of the site was that the reviews had two parts. The first part is spoiler-free, just giving a recommendation with some context to make up your own mind. The second part contained a reflection of the movie, which included spoilers.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://louwrentius.com/static/images/moevieoldgroot.webp"&gt;&lt;img alt="moevie" src="https://louwrentius.com/static/images/moeviecropped.webp" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Even back then, the site didn't win any design awards (from archive.org - click to enlarge)&lt;sup id="fnref:sorry"&gt;&lt;a class="footnote-ref" href="#fn:sorry"&gt;2&lt;/a&gt;&lt;/sup&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I started building the site a few months after finishing college (IT) in 2002 as I felt inept and had little confidence. Building something tangible felt like a good way to build up and demonstrate skills. And I had something to say about movies.&lt;/p&gt;
&lt;p&gt;Although moevie.nl did not help me gain employment as far as I know, it was fun while it lasted. At some point, I didn't get much joy out of writing movie reviews and I let the site die. &lt;/p&gt;
&lt;p&gt;I did keep backups of the database the code and the pictures though. And now after 18+ years I decided to &lt;a href="https://moevie.nl"&gt;resurrect the site&lt;/a&gt;, including all (old) reviews.&lt;/p&gt;
&lt;h2&gt;Why resurrect a dead website gone for 16+ years?&lt;/h2&gt;
&lt;p&gt;Rebuilding the site was just a way to spend time, a small hobby project. Something to be bussy with. The second reason is some kind of misplaced nostalgia. I sometimes regret shutting down the site, wondering what could have been if I persevered.&lt;/p&gt;
&lt;h2&gt;Losing and regaining the domain&lt;/h2&gt;
&lt;p&gt;Back in 2006, my hosting provider (non-profit with just a few servers) abruptly stopped operating due to hardware failure &lt;sup id="fnref:neglect"&gt;&lt;a class="footnote-ref" href="#fn:neglect"&gt;3&lt;/a&gt;&lt;/sup&gt; and I was forced to move my domain to another company. At that time, private citizens in The Netherlands could not register an .nl domain, only businesses could, so that was a bit of a hassle.&lt;/p&gt;
&lt;p&gt;Not long thereafter however, I decided to let the domain expire. It was quickly scooped up by 'domain resellers'. Years later I decided that I wanted moevie.nl back, but the sellers always asked insane amounts of money.&lt;/p&gt;
&lt;p&gt;In 2019, I visited moevie.nl on a whim. To my surprise it didn't resolve anymore, the domain was available! I quickly scooped it up, but I didn't do much with it for a long time, until now.&lt;/p&gt;
&lt;h2&gt;Rebuilding the site&lt;/h2&gt;
&lt;p&gt;I really wanted to preserve the aesthetic of moevie.nl as it was back then. Especially in the context of modern web design, it does stand out. As a sore thumb - but still - I had a goal.&lt;/p&gt;
&lt;p&gt;Having the code and database dump is one thing, but it doesn't tell you what it actually looked like in 2003-2006. I could have tried to get the old (PHP4) code working, but I just didn't feel like it.&lt;/p&gt;
&lt;p&gt;Instead, I chose to visit &lt;a href="https://archive.org"&gt;Archive.org&lt;/a&gt; and indeed, it captured old snapshots of my site back in 2006. So those were of great help. The screenshots at the top of this blog post are lifted from this &lt;a href="https://web.archive.org/web/20060102013434/http://www.moevie.nl/"&gt;page&lt;/a&gt; on archive.org. This snapshot was taken just before I decided to close the site. &lt;/p&gt;
&lt;h2&gt;The challenge of mobile device screens&lt;/h2&gt;
&lt;p&gt;To set the stage a bit: the rise and fall of moevie.nl happened a year before the iPhone was first announced. Smartphones from Blackberry were popular. I had a &lt;a href="https://en.wikipedia.org/wiki/Palm_Vx"&gt;Palm VX&lt;/a&gt; PDA and later a &lt;a href="https://nl.wikipedia.org/wiki/IPAQ"&gt;HP Compaq PDA&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Most people didn't have mobile data connections so as far as I know, the mobile web really wasn't a thing yet.&lt;/p&gt;
&lt;p&gt;So moevie.nl was primarily developed for the desktop. When I thought I was finished rebuilding the site, I quickly discovered that the site was &lt;em&gt;unusable&lt;/em&gt; on my iPhone and way too small and finicky to use on my iPad.&lt;/p&gt;
&lt;p&gt;For somebody who has no experience with modern web development, it was quite a steep learning-curve discovering how to deal with the various screen sizes in CSS&lt;sup id="fnref:issues"&gt;&lt;a class="footnote-ref" href="#fn:issues"&gt;4&lt;/a&gt;&lt;/sup&gt;. &lt;/p&gt;
&lt;p&gt;A very large part of the entire effort of rebuilding the site was spend on making the site workable on all different device sizes. Fortunately, iOS device simulators were of great help on that front. &lt;/p&gt;
&lt;h2&gt;Technology&lt;/h2&gt;
&lt;p&gt;I've recreated moevie.nl with Python and Django. For the database, I chose Postgresql, although that is total overkill, I could have used SQLite without any issues. &lt;/p&gt;
&lt;p&gt;I chose Django because I'm quite familiar with Python so that was a straight-forward choice. I selected Postgresql mostly just to regain some knowledge about it.&lt;/p&gt;
&lt;h2&gt;Hosting&lt;/h2&gt;
&lt;p&gt;I'm self-hosting moevie.nl on the same Raspbery Pi4 that is hosting this blog.
This Raspberry Pi is powered by &lt;a href="https://louwrentius.com/this-blog-is-now-running-on-solar-power.html"&gt;the sun&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;So moevie.nl is solar-powered during the day and battery-powered during the night. &lt;/p&gt;
&lt;h2&gt;Closing words&lt;/h2&gt;
&lt;p&gt;I'm not sure if I really want to start writing movie reviews again, knowing full well how much effort it takes. Also I'm not sure I have anything to say about movies anymore, but we'll see.&lt;/p&gt;
&lt;p&gt;The overall experience of rebuilding the site was frustrating at times due to the severe lack of experience and knowledge. Now that the site is done and working, even on mobile devices, that feels good.&lt;/p&gt;
&lt;div class="footnote"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:name"&gt;
&lt;p&gt;The name is based on the phonetic pronunciation in Dutch of the English word 'movie'.&amp;#160;&lt;a class="footnote-backref" href="#fnref:name" title="Jump back to footnote 1 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:sorry"&gt;
&lt;p&gt;sorry for the language but I could not find a better screenshot.&amp;#160;&lt;a class="footnote-backref" href="#fnref:sorry" title="Jump back to footnote 2 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:neglect"&gt;
&lt;p&gt;I was neglecting the site at that time due to losing motivation.&amp;#160;&lt;a class="footnote-backref" href="#fnref:neglect" title="Jump back to footnote 3 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:issues"&gt;
&lt;p&gt;I admit I only tested with iOS devices so Android-based smartphones could experience issues.&amp;#160;&lt;a class="footnote-backref" href="#fnref:issues" title="Jump back to footnote 4 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content><category term="Uncategorized"/><category term="web"/></entry><entry><title>Cryptocurrencies are detrimental to society</title><link href="https://louwrentius.com/cryptocurrencies-are-detrimental-to-society.html" rel="alternate"/><published>2020-03-27T12:00:00+01:00</published><updated>2020-03-27T12:00:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2020-03-27:/cryptocurrencies-are-detrimental-to-society.html</id><summary type="html">&lt;p&gt;Want to listen to this article?&lt;/p&gt;
&lt;figure&gt;
    &lt;audio
        controls
        src="https://louwrentius.com/files/audio/20190327_cryptocurrencies.mp3"&gt;
            Your browser does not support the
            &lt;code&gt;audio&lt;/code&gt; element.
    &lt;/audio&gt;
&lt;/figure&gt;

&lt;h2&gt;Introduction&lt;/h2&gt;
&lt;p&gt;How would you explain the inner workings of bitcoin to a person in simple, understandable terms? &lt;/p&gt;
&lt;p&gt;&lt;a href="https://twitter.com/am_anatiala/status/1030223326826950656"&gt;&lt;img alt="twitterimage" src="https://louwrentius.com/static/images/sudokusforheroin.png" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://twitter.com/am_anatiala/status/1030223326826950656"&gt;source&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This explanation seems perfect to me because it illustrates some seriously problematic aspects of cryptocurrencies in one simple …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Want to listen to this article?&lt;/p&gt;
&lt;figure&gt;
    &lt;audio
        controls
        src="https://louwrentius.com/files/audio/20190327_cryptocurrencies.mp3"&gt;
            Your browser does not support the
            &lt;code&gt;audio&lt;/code&gt; element.
    &lt;/audio&gt;
&lt;/figure&gt;

&lt;h2&gt;Introduction&lt;/h2&gt;
&lt;p&gt;How would you explain the inner workings of bitcoin to a person in simple, understandable terms? &lt;/p&gt;
&lt;p&gt;&lt;a href="https://twitter.com/am_anatiala/status/1030223326826950656"&gt;&lt;img alt="twitterimage" src="https://louwrentius.com/static/images/sudokusforheroin.png" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://twitter.com/am_anatiala/status/1030223326826950656"&gt;source&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This explanation seems perfect to me because it illustrates some seriously problematic aspects of cryptocurrencies in one simple sentence.&lt;/p&gt;
&lt;p&gt;It captures the unimaginable &lt;em&gt;energy waste&lt;/em&gt; of mining cryptocurrencies. And it also captures the dark side of cryptocurrencies: &lt;em&gt;facilitating crime&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;At this point cryptocurrency enthusiasts are rolling their eyes and sigh. This point has been made many times over. I know, I'm definitely not the first to criticise cryptocurrencies&lt;sup id="fnref:fn1"&gt;&lt;a class="footnote-ref" href="#fn:fn1"&gt;1&lt;/a&gt;&lt;/sup&gt; this way.&lt;/p&gt;
&lt;p&gt;I do have a simple challenge though:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Can you please show me the benefit to society of cryptocurrencies?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Please, don't come up with theoretical or future possibilities. Cryptocurrencies have existed for &lt;em&gt;eleven years&lt;/em&gt;, they should have something to show for &lt;em&gt;right now&lt;/em&gt;. After many hours of reading up on the topic, I have not been able to find any tangible benefits that would justify the effort and resources spend on them.&lt;/p&gt;
&lt;p&gt;The downsides of cryptocurrencies are an entirely different matter. They are very, very clear to me. But let's not go there directly. What fun would that be?&lt;/p&gt;
&lt;h2&gt;The solution in search of a problem&lt;/h2&gt;
&lt;p&gt;As I see it, cryptocurrencies are entangled in a desparate search for a problem to solve. They are the answer to a question nobody asked&lt;sup id="fnref:asked"&gt;&lt;a class="footnote-ref" href="#fn:asked"&gt;2&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;Many cryptocurrency advocates see the decentralised (distributed) nature of cryptocurrencies as a tangible benefit. Cryptocurrencies are most often not controlled by any government or single entity.&lt;/p&gt;
&lt;p&gt;Aside from whether this is true in practice&lt;sup id="fnref:aside"&gt;&lt;a class="footnote-ref" href="#fn:aside"&gt;3&lt;/a&gt;&lt;/sup&gt;, they seem to imply that it's a bad thing that governments control their own currencies. Well, last time I checked governments control their currencies to keep them as stable as possible. Frankly, that actually sounds like exactly what I would want from a currency. &lt;/p&gt;
&lt;p&gt;Stability.&lt;/p&gt;
&lt;p&gt;You can call cryptocurrencies many things but 'stable' is definitely not one of them. Cryptocurrencies are highly volatile. In cryptocoin, a loaf of bread could suddenly cost twice as much as the day before.&lt;/p&gt;
&lt;p&gt;Although cryptocurrencies haven't seen any significant adoption as a payment method - due to their volatility - it has seen adoption in 'less stable countries' where it is basically the &lt;a href="https://bitcoinist.com/bitcoin-rescue-economically-unstable-countries/"&gt;'lesser of two evils'&lt;/a&gt;. I mean: you know things are bad if a volatile cryptocurrency is a safer option than the native currency of your country.&lt;/p&gt;
&lt;p&gt;The argument in the end boils down to: if your society is already &lt;em&gt;in serious trouble&lt;/em&gt;, maybe cryptocurrencies could provide 'some benefit'. If the people involved have reliable access to internet. And internet access is most often controlled by the government.&lt;/p&gt;
&lt;p&gt;To my knowledge, cryptocurrency as a payment method has actually only seen true adoption within the world of dark markets such as &lt;a href="https://en.wikipedia.org/wiki/Silk_Road_(marketplace)"&gt;Silk Road&lt;/a&gt; in wich bitcoin rose to prominence. Nonetheless, after eleven years, cryptocurrencies have no traction in the regular 'legitimate' markets as a real payment method. &lt;/p&gt;
&lt;p&gt;The reason why is obvious: existing payment methods are much easier to use and feel much safer. And the volatility of cryptocurrencies only compounds to the support of these conventional methods.&lt;/p&gt;
&lt;p&gt;If cryptocurrencies are a solution to anything at all they seem to be 'bad' solutions at best.&lt;/p&gt;
&lt;h2&gt;Are cryptocurrencies in fact a Ponzi or Piramid scheme?&lt;/h2&gt;
&lt;p&gt;It depends on the particular currency, but I think the &lt;a href="https://www.counterpunch.org/2018/02/09/is-cryptocurrency-a-ponzi-scheme/"&gt;case can be made for sure&lt;/a&gt;. I mean: why not both?&lt;/p&gt;
&lt;p&gt;Cryptocurrencies &lt;a href="https://www.forbes.com/sites/jayadkisson/2018/04/14/bitcoin-and-cryptocurrency-unsuitable-at-any-speed/"&gt;have no intrinsic value&lt;/a&gt;. They are only worth what people are willing to pay for them. So the cryptocurrency advocates needed to drum up demand, to create a market where previously none existed. This resulted in wild visions of the future, elaborate jargon-filled smokescreens that argue cryptocurrencies would take over the world. Get in quickly or you miss out!&lt;/p&gt;
&lt;p&gt;And so many people were afraid to miss out, creating an enormous cryptocurrency hype, starting in November of 2017, spilling into 2018 when the bubble burst. The end result? A few people got very rich and the vast majority lost money.&lt;/p&gt;
&lt;p&gt;It seems to me this all is a combination of a &lt;a href="https://en.wikipedia.org/wiki/Ponzi_scheme"&gt;ponzi scheme&lt;/a&gt; with the component of active recruitment found in &lt;a href="https://en.wikipedia.org/wiki/Pyramid_scheme"&gt;piramid schemes&lt;/a&gt;. The value of the currencies must come from somewhere, right?&lt;/p&gt;
&lt;p&gt;So please tell me how all of this benefits our society? Creating a handful of rich people at the expense of a lot of other people? &lt;a href="https://qz.com/1217460/cryptocurrency-is-a-giant-multi-level-marketing-scheme/"&gt;Is that it&lt;/a&gt;? &lt;/p&gt;
&lt;p&gt;The graveyard of &lt;a href="https://deadcoins.com"&gt;dead cryptocurrencies&lt;/a&gt; only shows how many people or startups try to get a piece of the action. And so many of them are outright scams. Are in fact all cryptocurrencies scams at their core?&lt;/p&gt;
&lt;h2&gt;The downsides of cryptocurrencies&lt;/h2&gt;
&lt;p&gt;I hope I have established that cryptocurrencies provide no tangible benefits to society. But the do have a lot of downsides. I observe the following: &lt;/p&gt;
&lt;table border="1" cellpadding="7" cellspacing="2" vertical-align="top"&gt;
&lt;tr&gt;&lt;th width=280px&gt;Topic&lt;/th&gt;&lt;th&gt;Remark&lt;/th&gt;
&lt;tr&gt;&lt;td&gt;Trafficing of illegal goods&lt;/td&gt;&lt;td&gt;Drugs, weapons, childpornography, and so on.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Trafficing of illegal services&lt;/td&gt;&lt;td&gt;Murder for hire&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Tax evasion&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Money laundering&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Ransomware&lt;/td&gt;&lt;td&gt;Hold data hostage in encrypted form&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Polution / energy waste&lt;/td&gt;&lt;td&gt;crypto miners use a lot of electricity&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Lack of Security&lt;/td&gt;&lt;td&gt;several cryptocurrency exchanges have been hacked&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Crypto scams&lt;/td&gt;&lt;td&gt;New cryptocoins are created just to scam people&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;

&lt;p&gt;The easy retort to this table is: "'normal' currencies like the dollar or euro also facilitate almost all of those illegal things", which is true but it misses the larger point. &lt;/p&gt;
&lt;p&gt;Those regular currencies provide tremendous value to our societies. Our societies are build upon them and they facilitate almost everything we do. The topics listed in the table are just a possible negative side-effect for regular currencies. Their clear benefits outweighs such downsides.&lt;/p&gt;
&lt;p&gt;Cryptocurrencies don't seem to have any such upsides. They seem to be made to exclusively facilitate cryptocurrency speculation and crime.&lt;/p&gt;
&lt;h2&gt;Cryptocurrencies facilitate crime&lt;/h2&gt;
&lt;p&gt;I won't discuss all the topics in the previous table but I do want to highlight a few.&lt;/p&gt;
&lt;h3&gt;Dark markets&lt;/h3&gt;
&lt;p&gt;I think we all remember &lt;a href="https://en.wikipedia.org/wiki/Silk_Road_(marketplace)"&gt;Silk Road&lt;/a&gt;, a now defunct &lt;a href="https://en.wikipedia.org/wiki/Darknet_market"&gt;darknet marketplace&lt;/a&gt; that allowed people to anonymously buy - amongst other things - drugs and guns&lt;sup id="fnref:snfn"&gt;&lt;a class="footnote-ref" href="#fn:snfn"&gt;4&lt;/a&gt;&lt;/sup&gt;.
Silk Road was the first large-scale application of bitcoin as a means of payment.&lt;/p&gt;
&lt;p&gt;Silk Road started out with just drugs, but guns soon followed. This deeply depraved world of dark markets &lt;a href="https://www.nytimes.com/2020/01/28/technology/bitcoin-black-market.html"&gt;are very much enabled&lt;/a&gt; by cryptocurrencies because the parties involved in a transaction are so hard to identify.&lt;/p&gt;
&lt;h3&gt;Ransomware&lt;/h3&gt;
&lt;p&gt;Ransomware seems to be almost exclusively enabled by digital currencies. Not explicitly just cryptocurrencies, but they do enable this type of crime because tracing the payments back to the criminal is so difficult.&lt;/p&gt;
&lt;p&gt;The damage caused by ransomware is so obviously devastating. You can have many opinions on the fact that many critical organisations such as hospitals or universities don't have their computer security under control. &lt;/p&gt;
&lt;p&gt;The real problem is that cryptocurrencies make these kinds of attacks on businesses and institutions very low-risk and highly profitable. In my own country a &lt;a href="https://www.dutchnews.nl/news/2020/01/maastricht-university-paid-hackers-to-get-back-system-access/"&gt;university&lt;/a&gt; was targeted by such an attack and allegedly they paid the ransom. The disruption to its services was substantial.&lt;/p&gt;
&lt;h2&gt;Energy waste&lt;/h2&gt;
&lt;p&gt;As cryptocurrencies rose in value, it started to become profitable to 'mine' them. It started out with regular computers, but soon, we could use videocards to accelerate cryptocurrency mining, which are very power hungry. &lt;/p&gt;
&lt;p&gt;Later on, FPGAs and ASICS were build to further accelerate mining performance. Entire companies spun up to build those miners and host them in large datacenters with cheap electricity. The scale of the operation is rather enormous. &lt;/p&gt;
&lt;p&gt;According to an &lt;a href="https://www.forbes.com/sites/niallmccarthy/2019/07/08/bitcoin-devours-more-electricity-than-switzerland-infographic/"&gt;article dating to July 2019&lt;/a&gt;, just bitcoin mining consumes more electricity than Switzerland. The article links to an &lt;a href="https://www.cbeci.org"&gt;online tool&lt;/a&gt; that tracks this power usage in real-time based on some estimates. &lt;/p&gt;
&lt;p&gt;&lt;a href="https://commons.wikimedia.org/wiki/File:Cryptocurrency_Mining_Farm.jpg"&gt;&lt;img alt="mf" src="https://louwrentius.com/static/images/miningfarm.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;a href="https://commons.wikimedia.org/wiki/File:Cryptocurrency_Mining_Farm.jpg"&gt;Image source&lt;/a&gt;&lt;/em&gt; &lt;/p&gt;
&lt;p&gt;It's just mind boggling to me that so much energy is wasted, so much pressure is put on the environment, for absolutely no clear benefit at all. &lt;/p&gt;
&lt;h2&gt;Closing words&lt;/h2&gt;
&lt;p&gt;So in short, I think that cryptocurrencies provide nothing of value to society. They do however facilitate crime and contribute to climate change.&lt;/p&gt;
&lt;p&gt;Therefore, I would propose to shut them all down.&lt;/p&gt;
&lt;p&gt;The complex technology behind the cryptocurrencies attracted a lot of otherwise smart people and I think it's a sad thing to see their efforts going to waste or have a negative impact. &lt;/p&gt;
&lt;p&gt;People are not obliged to work on something valuable, but at least may I ask that they choose to work on something that won't harm our society?&lt;/p&gt;
&lt;p&gt;Link to &lt;a href="https://news.ycombinator.com/item?id=22703081"&gt;hackernews&lt;/a&gt;, where this post was quickly flagged down. The few comments that exist don't seem to really provide any answers to the question I pose.&lt;/p&gt;
&lt;div class="footnote"&gt;
&lt;hr /&gt;
&lt;ol&gt;
&lt;li id="fn:fn1"&gt;
&lt;p&gt;I would definitely recommend reading this &lt;a href="https://www.newyorker.com/magazine/2018/10/22/the-prophets-of-cryptocurrency-survey-the-boom-and-bust"&gt;long-form-article&lt;/a&gt; by The New York Times.&amp;#160;&lt;a class="footnote-backref" href="#fnref:fn1" title="Jump back to footnote 1 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:asked"&gt;
&lt;p&gt;Unless you want to embark on a path of criminal activity.&amp;#160;&lt;a class="footnote-backref" href="#fnref:asked" title="Jump back to footnote 2 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:aside"&gt;
&lt;p&gt;As mining is no longer profitable for the larger community, the miners become a small concentrated group of entities controlling the currency, making the currencies more centralised. Furthermore, the cryptocurrency exchanges where you can convert the cryptocurrency into regular money, are centralised institutions backed by for-profit companies. And those companies have to abide by the law. They are under the &lt;a href="https://www.loc.gov/law/help/cryptocurrency/world-survey.php"&gt;influence&lt;/a&gt; of the government.&amp;#160;&lt;a class="footnote-backref" href="#fnref:aside" title="Jump back to footnote 3 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:snfn"&gt;
&lt;p&gt;If you want to know more about what happend to Silk Road and it's founder - 'the Dread Pirate Roberts', I would recommend the book &lt;a href="http://www.americankingpin.com/"&gt;'American Kingpin'&lt;/a&gt; by Nick Bilton. (no affiliate links)&amp;#160;&lt;a class="footnote-backref" href="#fnref:snfn" title="Jump back to footnote 4 in the text"&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content><category term="Uncategorized"/><category term="None"/></entry><entry><title>FreeBSD 10.1 unattended install over PXE &amp; HTTP (no NFS)</title><link href="https://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" rel="alternate"/><published>2015-01-16T12:00:00+01:00</published><updated>2015-01-16T12:00:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2015-01-16:/freebsd-101-unattended-install-over-pxe-http-no-nfs.html</id><summary type="html">&lt;p&gt;To gain some more experience with FreeBSD, I decided to make a PXE-based unattended installation of FreeBSD 10.1. &lt;/p&gt;
&lt;p&gt;My goal is to set something up similar to Debian/Ubuntu + preseeding or Redhat/CentOS + kickstart.&lt;/p&gt;
&lt;p&gt;Getting a PXE-based unattended installation of FreeBSD 10.1 was not easy and I was …&lt;/p&gt;</summary><content type="html">&lt;p&gt;To gain some more experience with FreeBSD, I decided to make a PXE-based unattended installation of FreeBSD 10.1. &lt;/p&gt;
&lt;p&gt;My goal is to set something up similar to Debian/Ubuntu + preseeding or Redhat/CentOS + kickstart.&lt;/p&gt;
&lt;p&gt;Getting a PXE-based unattended installation of FreeBSD 10.1 was not easy and I was unable to automate a ZFS-based install using bsdinstall.&lt;/p&gt;
&lt;p&gt;I would expect someting like the netboot install &lt;/p&gt;
&lt;p&gt;Below, I've documented what I've done to do a basic installation of FreeBSD using only DHCP, TFTP, no NFS required.  &lt;/p&gt;
&lt;h3&gt;Overview of all the steps:&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;have a working DHCP with PXE boot options &lt;/li&gt;
&lt;li&gt;have a working TFTP server&lt;/li&gt;
&lt;li&gt;customise your pxelinux boot menu&lt;/li&gt;
&lt;li&gt;install a FreeBSD box manually, or use an existing one&lt;/li&gt;
&lt;li&gt;download and install &lt;a href="http://mfsbsd.vx.sk"&gt;mfsbsd&lt;/a&gt; on the FreeBSD system&lt;/li&gt;
&lt;li&gt;download a FreeBSD release iso image on the FreeBSD system &lt;/li&gt;
&lt;li&gt;configure and customise your FreeBSD PXE boot image settings&lt;/li&gt;
&lt;li&gt;build the PXE boot image and copy it to your TFTP server&lt;/li&gt;
&lt;li&gt;PXE boot your system and boot the FreeBSD image &lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Setting up a DHCP server + TFTP server&lt;/h3&gt;
&lt;p&gt;Please take a look at &lt;a href="https://louwrentius.com/automated-install-of-debian-linux-based-on-pxe-net-booting.html"&gt;another article&lt;/a&gt; I wrote on setting up PXE booting.&lt;/p&gt;
&lt;h3&gt;Configuring the PXE boot menu&lt;/h3&gt;
&lt;p&gt;Add these lines to your PXE Menu:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;LABEL FreeBSD10
kernel memdisk
append initrd=BSD/FreeBSD/10.1/mfsbsd-10.1-RC3-amd64.img harddisk raw
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h3&gt;Setup or gain access to a FreeBSD host&lt;/h3&gt;
&lt;p&gt;You need to setup or gain access to a FreeBSD system, because the mfsbsd tool only works on FreeBSD. You will use this system to generate a FreeBSD PXE boot image.&lt;/p&gt;
&lt;h3&gt;Installing mfsbsd&lt;/h3&gt;
&lt;p&gt;First we download &lt;a href="http://mfsbsd.vx.sk"&gt;mfsbsd&lt;/a&gt;. &lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;fetch http://mfsbsd.vx.sk/release/mfsbsd-2.1.tar.gz
tar xzf mfsbsd-2.1.tar.gz
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Then we get a FreeBSD ISO:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;fetch http://ftp.freebsd.org/pub/FreeBSD/releases/ISO-IMAGES/10.1/FreeBSD-10.1-RELEASE-amd64-disc1.iso
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Mount the ISO:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;mdconfig -a -t vnode -f /root/FreeBSD-10.1-RELEASE-amd64-disc1.iso
mount_cd9660 /dev/md0 /cdrom/
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h3&gt;setup rc.local&lt;/h3&gt;
&lt;p&gt;Enter the mfsbsd-2.1 directory. Put the following content in the conf/rc.local file.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;fetch http://&amp;lt;yourwebserver&amp;gt;/pxe/installerconfig -o /etc/installerconfig
tail -n 7 /etc/rc.local &amp;gt; /tmp/start.sh
chmod +x /tmp/start.sh
/tmp/start.sh 
exit 0

#!/bin/csh
setenv DISTRIBUTIONS &amp;quot;kernel.txz base.txz&amp;quot;
setenv BSDINSTALL_DISTDIR /tmp
setenv BSDINSTALL_DISTSITE
ftp://ftp.freebsd.org/pub/FreeBSD/releases/amd64/10.1-RELEASE

bsdinstall distfetch 
bsdinstall script /etc/installerconfig
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;As you can see there is a script within a script that is executed separately by rc.local. That's a bit ugly but it does work.&lt;/p&gt;
&lt;h3&gt;setup installerconfig (FreeBSD unattended install)&lt;/h3&gt;
&lt;p&gt;The 'installerconfig' script is a script in a special format used by the bsdinstall tool to automate the installation. The top is used to control variables used during the unattended installation. The bottom is a script executed post-install chrooted on the new system. &lt;/p&gt;
&lt;p&gt;Put this in 'installerconfig'&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;PARTITIONS=da0
DISTRIBUTIONS=&amp;quot;kernel.txz base.txz&amp;quot;
BSDINSTALL_DISTDIR=/tmp
BSDINSTALL_DISTSITE=ftp://ftp.freebsd.org/pub/FreeBSD/releases/amd64/10.1-RELEASE

#!/bin/sh
echo &amp;quot;Installation complete, running in host system&amp;quot;
echo &amp;quot;hostname=\&amp;quot;FreeBSD\&amp;quot;&amp;quot; &amp;gt;&amp;gt; /etc/rc.conf
echo &amp;quot;autoboot_delay=\&amp;quot;5\&amp;quot;&amp;quot; &amp;gt;&amp;gt; /boot/loader.conf
echo &amp;quot;sshd_enable=YES&amp;quot; &amp;gt;&amp;gt; /etc/rc.conf
echo &amp;quot;Setup done&amp;quot; &amp;gt;&amp;gt; /tmp/log.txt
echo &amp;quot;Setup done.&amp;quot;
poweroff
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;As you can see, the post-install script enables SSH, sets the hostname and reduced the autoboot delay.&lt;/p&gt;
&lt;p&gt;Please note that I faced an issue where the bsdinstall program would not interpret the options set in the installerconfig script. This is why I exported them with 'setenv' in the rc.local script.&lt;/p&gt;
&lt;p&gt;With Debian preseeding or Redhat kickstarting, you can host the preseed or kickstart file on a webserver. Changing the PXE-based installation is just a matter of edditing the preseed or kickstart file on the webserver. &lt;/p&gt;
&lt;p&gt;Because it's not fun having to generate a new image every time your want to update your unattended installation, it's recommended to host the installerconfig file on a webserver, as if it is a preseed or kickstart file. &lt;/p&gt;
&lt;p&gt;This saves you from having to regenerate the PXE-boot image file every time.&lt;/p&gt;
&lt;p&gt;You can still put the installer config in the image itself. If you want a fixed 'installerconfig' file containing the bsdinstall instructions, put this file also in the 'conf' directory. Next, edit the Makefile. Search for this string:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;.for FILE in rc.conf ttys
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;For me, it was at line 315. Change it to:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;.for FILE in rc.conf ttys installerconfig
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h3&gt;Building the PXE boot image&lt;/h3&gt;
&lt;p&gt;Now everything is configured, we can generate the boot image with mfsbsd. 
Run 'make'. Then when it fails with this error:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;Creating image file ...
/root/mfsbsd-2.1/tmp/mnt: write failed, filesystem is full
*** Error code 1

Stop.
make: stopped in /root/mfsbsd-2.1
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;just run 'make' again. In my experience, make worked the second time, consistently. I'm not sure why this happens. &lt;/p&gt;
&lt;p&gt;The end result of this whole process is a file like 'mfsbsd-se-10.1-RC3-amd64.img'. &lt;/p&gt;
&lt;p&gt;You can copy this image to the appropriate folder on your TFTP server. In my example it would be:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;/srv/tftp/BSD/FreeBSD/10.1/mfsbsd-10.1-RC3-amd64.img
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h3&gt;Test the PXE installation&lt;/h3&gt;
&lt;p&gt;Boot a test machine from PXE and boot your custom generated image. &lt;/p&gt;
&lt;h3&gt;Final words&lt;/h3&gt;
&lt;p&gt;I'm a bit unhappy about how difficult it was to create an PXE-based unattended FreeBSD installation. The bsdinstall installation software seems buggy to me. However, it could be just me: that I have misunderstood how it al works. However, I can't seem to find any documentation on how to properly use the bsdinstall system for an unattended installation. &lt;/p&gt;
&lt;p&gt;If anyone has suggestions or ideas to implement an unattended bsdinstall script 'properly', with ZFS support, I'm all ears.&lt;/p&gt;
&lt;p&gt;This is the recipe I tried to use to get a root-on-zfs install:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;ZFSBOOT_POOL_NAME=TEST_ROOT
ZFSBOOT_VDEV_TYPE=mirror
ZFSBOOT_POOL_SIZE=10g
ZFSBOOT_DISKS=&amp;quot;da0 da1&amp;quot;
ZFSBOOT_SWAP_SIZE=2g
ZFSBOOT_CONFIRM_LAYOUT=1
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The installer would never recognise the second disk and the script would get stuck. &lt;/p&gt;
&lt;p&gt;I'm aware that mfsbsd has an option to use a custom root-on-zfs script, but I wanted to use the 'official' FreeBSD tools. &lt;/p&gt;</content><category term="Uncategorized"/><category term="PXE"/></entry><entry><title>Finding a good blu-ray player for Mac OS X</title><link href="https://louwrentius.com/finding-a-good-blu-ray-player-for-mac-os-x.html" rel="alternate"/><published>2013-09-22T18:00:00+02:00</published><updated>2013-09-22T18:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2013-09-22:/finding-a-good-blu-ray-player-for-mac-os-x.html</id><summary type="html">&lt;p&gt;I find playing a Blu-ray movie on my Mac cumbersome. I've been using &lt;a href="http://www.plexapp.com"&gt;Plex&lt;/a&gt;, &lt;a href="http://xbmc.org"&gt;XBMC&lt;/a&gt; and &lt;a href="http://www.videolan.org/vlc/index.html"&gt;VLC&lt;/a&gt; but these free open-source products are all a usability nightmare. &lt;/p&gt;
&lt;p&gt;To play a Blu-ray movie, you have to perform these steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;right-click on the BDMV file&lt;/li&gt;
&lt;li&gt;choose 'show packet contents'&lt;/li&gt;
&lt;li&gt;go to the …&lt;/li&gt;&lt;/ol&gt;</summary><content type="html">&lt;p&gt;I find playing a Blu-ray movie on my Mac cumbersome. I've been using &lt;a href="http://www.plexapp.com"&gt;Plex&lt;/a&gt;, &lt;a href="http://xbmc.org"&gt;XBMC&lt;/a&gt; and &lt;a href="http://www.videolan.org/vlc/index.html"&gt;VLC&lt;/a&gt; but these free open-source products are all a usability nightmare. &lt;/p&gt;
&lt;p&gt;To play a Blu-ray movie, you have to perform these steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;right-click on the BDMV file&lt;/li&gt;
&lt;li&gt;choose 'show packet contents'&lt;/li&gt;
&lt;li&gt;go to the STREAM folder&lt;/li&gt;
&lt;li&gt;sort the files by size (from large to small)&lt;/li&gt;
&lt;li&gt;select the biggest m2ts file and open it in the appropriate player&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I got so fed-up with this process that I started searching for any product that just allows me to point it to a folder with Blu-ray content and friggin' play it. Fortunately, there is such a product for Mac OS X, it's called &lt;a href="http://www.macblurayplayer.com"&gt;Mac Blu-ray Player&lt;/a&gt; and it's a paid application. I paid 36 euro (48 dollar) including taxes. &lt;/p&gt;
&lt;p&gt;Those 36 euros are well spend. No it is not free, no it is not open-source, but I don't care. It is a good product. If you value your time I highly recommend buying this software. &lt;/p&gt;
&lt;p&gt;I don't have anything against free or open-source software, but I do have a grudge against software that is not user-friendly. If software is not easy to use, something you would expect from a media player, it's broken.&lt;/p&gt;
&lt;p&gt;Fortunately, you don't have to trust me on my word, you can download a free trial that seems fully functional, it only shows a trial message when playing a movie. &lt;/p&gt;</content><category term="Uncategorized"/><category term="blu-ray"/><category term="Mac OS X"/></entry><entry><title>I switched my blog from Blogofile to Pelican</title><link href="https://louwrentius.com/i-switched-my-blog-from-blogofile-to-pelican.html" rel="alternate"/><published>2013-08-06T03:00:00+02:00</published><updated>2013-08-06T03:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2013-08-06:/i-switched-my-blog-from-blogofile-to-pelican.html</id><summary type="html">&lt;p&gt;This blog is a static website, which makes it fast, simple and secure. It was generated by &lt;a href="http://www.blogofile.com/"&gt;Blogofile&lt;/a&gt; but I switched to &lt;a href="http://blog.getpelican.com/"&gt;Pelican&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Blogofile has seen almost no updates over the years and I consider the project dead. Realising that blogofile is dead, I decided to look around for different …&lt;/p&gt;</summary><content type="html">&lt;p&gt;This blog is a static website, which makes it fast, simple and secure. It was generated by &lt;a href="http://www.blogofile.com/"&gt;Blogofile&lt;/a&gt; but I switched to &lt;a href="http://blog.getpelican.com/"&gt;Pelican&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Blogofile has seen almost no updates over the years and I consider the project dead. Realising that blogofile is dead, I decided to look around for different open source static blog generators. &lt;/p&gt;
&lt;p&gt;There are many other static blog generators than pelican. But Pelican is well-documented, is based on Python, is very actively maintained (good track record) and supports all features that I wanted. Some of those features are  Atom/RSS, Disqus and Google analytics support. &lt;/p&gt;
&lt;p&gt;My blog posts are written using Markdown. This makes it very easy to migrate away from Blogofile to Pelican, as Pelican also supports Markdown. Blogofile uses a different header format not recognised by Pelican, so you have to search and replace some key words in all your files before Pelican can actually generate your new website.&lt;/p&gt;
&lt;p&gt;I wrote this horrible bash shell for-loop to process all my blog posts:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;    :::bash
    for x in *.md
    do
        TITLE=`grep -i &amp;quot;title:&amp;quot; &amp;quot;$x&amp;quot;`
        TITLEFIXED=`echo $TITLE | sed s/\&amp;quot;//g`
        DATE=`grep -i &amp;quot;date:&amp;quot; &amp;quot;$x&amp;quot;`
        DATEFIXED=`echo $DATE | sed &amp;quot;s/\//-/g&amp;quot; | cut -d &amp;quot;:&amp;quot; -f 1,2,3`
        CATEGORY=`grep -i &amp;quot;categories:&amp;quot; &amp;quot;$x&amp;quot;`
        CATEGORYFIXED=`echo $CATEGORY | sed s/\&amp;quot;//g | sed s/categories/category/g | cut -d &amp;quot;,&amp;quot; -f 1 | /usr/local/bin/sed -e &amp;quot;s/\b\(.\)/\u\1/g&amp;quot;`
        echo &amp;quot;$TITLEFIXED&amp;quot; &amp;gt; tmp.txt
        echo &amp;quot;$CATEGORYFIXED&amp;quot; &amp;gt;&amp;gt; tmp.txt
        echo &amp;quot;$DATEFIXED&amp;quot; &amp;gt;&amp;gt; tmp.txt
        grep -v &amp;quot;title:&amp;quot; &amp;quot;$x&amp;quot; | grep -v -e &amp;#39;---&amp;#39; | grep -v -i &amp;quot;date:&amp;quot; | grep -v -i &amp;quot;categories:&amp;quot; &amp;gt;&amp;gt; tmp.txt
        mv tmp.txt &amp;quot;$x&amp;quot;
    done
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Notice how Build-in syntax highlighting of Pelican applies nice colors to this horrible code. Regarding this horrible code: I had to use GNU sed as the Mac OS X sed did not support the regular expression I used. &lt;/p&gt;
&lt;p&gt;To enable comments for my blog posts I always used &lt;a href="http://disqus.com/"&gt;Disqus&lt;/a&gt; with Blogofile. Pelican generates web pages in a different way compared to blogofile, so all old pages need to be redirected to the new location. I used the redirect functionality of &lt;a href="http://redmine.lighttpd.net/projects/1/wiki/docs_modredirect"&gt;Lighttpd&lt;/a&gt; to redirect all existing pages to the new location. &lt;/p&gt;
&lt;p&gt;The cool thing is that Disqus has a tool called "Redirect Crawler". If you have configured 301 "permanent redirects" for all pages and run this tool, Disqus will automatically update all existing links to the new locations, so your comments are migrated to the new web pages. &lt;/p&gt;
&lt;p&gt;Furthermore, I've implemented a Pelican plugin called &lt;a href="https://github.com/jrarseneau/pelican-titlecase"&gt;titlecase&lt;/a&gt; which capitalizes the first letter of words in the title of your article. It's just that I think it looks better.&lt;/p&gt;
&lt;p&gt;I think I'm really happy with Pelican.&lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Why I believe the new Mac Pro won't be a great machine for gaming</title><link href="https://louwrentius.com/why-i-believe-the-new-mac-pro-wont-be-a-great-machine-for-gaming.html" rel="alternate"/><published>2013-06-23T00:00:00+02:00</published><updated>2013-06-23T00:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2013-06-23:/why-i-believe-the-new-mac-pro-wont-be-a-great-machine-for-gaming.html</id><summary type="html">&lt;p&gt;In &lt;a href="http://atp.fm/episodes/18-aluminum-colored-aluminum"&gt;Accidental Tech Podcast episode 18&lt;/a&gt; (love the show), I learned that John Siracusa was thinking about buying a new Mac Pro for gaming.&lt;/p&gt;
&lt;p&gt;I believe that gaming on the new Mac Pro will be a mediocre experience.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Driver support:&lt;/em&gt; as John mentioned himself, the video cards are 'professional GPUs' …&lt;/p&gt;</summary><content type="html">&lt;p&gt;In &lt;a href="http://atp.fm/episodes/18-aluminum-colored-aluminum"&gt;Accidental Tech Podcast episode 18&lt;/a&gt; (love the show), I learned that John Siracusa was thinking about buying a new Mac Pro for gaming.&lt;/p&gt;
&lt;p&gt;I believe that gaming on the new Mac Pro will be a mediocre experience.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Driver support:&lt;/em&gt; as John mentioned himself, the video cards are 'professional GPUs' used in workstations for computing, CAD etc. These cards and especially
their drivers under Windows are not geared towards gaming performance.&lt;/p&gt;
&lt;p&gt;The performance and quality of Mac OS X drivers may be improved dramatically over the past years, but if you like to play games exclusively under Windows,
you will probably be disappointed when you switch to bootcamp.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Crossfire support:&lt;/em&gt; you have these two ridiculously fast GPU's and for years on the PC platform, you can stack them together to achieve insane performance
(SLI / Crossfire).&lt;/p&gt;
&lt;p&gt;Mac OS X does not seem to support crossfire (or SLI). If you can't benefit from crossfire, you're paying a lot of money for a machine with one idle but very
expensive videocard. That sounds like a ridiculous waste of good money.&lt;/p&gt;
&lt;p&gt;Assuming that the hardware supports crossfire, if you would run Windows, then you may hit the driver issues associated with pro cards.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Upgrading:&lt;/em&gt; upgrading can be cost-efficient as most games are GPU not CPU bound, not an option for the Mac Pro. Even the new Thunderbolt interface does not have sufficient bandwidth to hook up one or more external high-performance videocards, aside from the fact that this will be insanely expensive.&lt;/p&gt;
&lt;p&gt;If you really needs the horsepower of a Mac Pro for other purposes than for gaming, sure it's the fastest mac you can get, but otherwise, I believe there's a better deal to be had.&lt;/p&gt;
&lt;p&gt;We don't now what the new Mac Pro will cost in a configuration suitable for gaming, but it will be 'a lot'. I believe that for one new Mac Pro, you will also be able to buy:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;a mac Mini with reasonable specs (it's easy to replace memory and storage); &lt;/li&gt;
&lt;li&gt;a high-quality 27" display @ 2560x1440 &lt;/li&gt;
&lt;li&gt;a ridiculously fast PC that will outperform the new Mac Pro when it comes to gaming.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I know that some Mac users don't like the idea of having a PC at home, but if you are into PC gaming, there's no other choice in my opinion if you want a good
gaming experience.&lt;/p&gt;
&lt;p&gt;I had high hopes for my 27" iMac (2011) but gaming performance anno 2013 is just mediocre at best. And I can't use it as an external display with a PC, only with a Mac.&lt;/p&gt;
&lt;p&gt;So I sold my 27" iMac and used the money to buy a separate 27" display and Mac Mini. I also ordered a 'ridiculously fast PC' which I hope will allow me to play all modern games on max quality settings for now and the upcoming year. And if required, I can swap out the dual GPUs and replace them with something better over time, if I need to.&lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Why VMware vSphere replication is changing the game</title><link href="https://louwrentius.com/why-vmware-vsphere-replication-is-changing-the-game.html" rel="alternate"/><published>2012-11-12T23:00:00+01:00</published><updated>2012-11-12T23:00:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2012-11-12:/why-vmware-vsphere-replication-is-changing-the-game.html</id><summary type="html">&lt;p&gt;If you are running a serious VMware environment, chances are you do have a SAN. Often with smaller setups, many people do employ multiple VMware hosts, but the SAN is a single point of failure.&lt;/p&gt;
&lt;p&gt;SANs are often fully redundant devices, with redundant PSUs, storage controllers, network links and RAID …&lt;/p&gt;</summary><content type="html">&lt;p&gt;If you are running a serious VMware environment, chances are you do have a SAN. Often with smaller setups, many people do employ multiple VMware hosts, but the SAN is a single point of failure.&lt;/p&gt;
&lt;p&gt;SANs are often fully redundant devices, with redundant PSUs, storage controllers, network links and RAID arrays.  But with all that redundancy build in, they still fail. I've seen it happen and a failing SAN is the worst.&lt;/p&gt;
&lt;p&gt;So I'd rather have two cheap entry level SANs if possible than just a single big one and keeping my fingers crossed that they won't fail.&lt;/p&gt;
&lt;p&gt;A redundant SAN environment where you basically deploy two separate SAN devices with their own storage needs a replication setup. And replication between SAN environments needs often extra licences or more expensive setups. And the replication mechanism must play well with your virtualisation layer, such as VMware.&lt;/p&gt;
&lt;p&gt;But the fun thing is that VMware made everything way simpler by integrating their own &lt;a href="http://www.google.nl/url?sa=t&amp;amp;rct=j&amp;amp;q=vmware%20vsphere%20replication%205.1&amp;amp;source=web&amp;amp;cd=1&amp;amp;cad=rja&amp;amp;sqi=2&amp;amp;ved=0CCYQFjAA&amp;amp;url=http%3A%2F%2Fwww.vmware.com%2Ffiles%2Fpdf%2Ftechpaper%2FIntroduction-to-vSphere-Replication.pdf&amp;amp;ei=0muhUPayNMfe4QS2woGIDg&amp;amp;usg=AFQjCNERmOjUUuCjMaNGBAU9RZ4--By4JQ"&gt;storage replication&lt;/a&gt; into their vSphere product. I have no experience whatsoever with VMware's new build-in replication feature. But I believe that it is significant. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://pubs.vmware.com/vsphere-51/topic/com.vmware.ICbase/PDF/vsphere-replication-51-admin.pdf"&gt;Replication&lt;/a&gt; is a new feature introduced in VMware vSphere 5.1 that is now part of the vSphere Essentials Plus Kit and vSphere Standard. So if you start with two or three VMware hosts and two entry-level SAN devices, you can be quite redundant and can have a fully redundant setup. And that will cost you around 3800 Euro ~ 4800 US dollar. &lt;/p&gt;
&lt;p&gt;The Essentials Plus Kit is a nice environment for smaller companies, but license-wise, it does not scale as you are stuck with a maximum of 6 physical CPUs and a maximum of three hosts. However it seems that when you need to expand beyond that capacity, you can trade in your existing license and obtain a discount when upgrading to - for example - vSphere Standard or Enterprise.&lt;/p&gt;
&lt;p&gt;The most significant thing about the build-in replication is that it does not matter any more what you use for your storage backend. If you use two entirely different devices from different vendors, that's OK. Because VMware handles all the replication stuff. Those SAN devices become just dumb storage boxes. Most of us just can configure whatever does support iSCSI.&lt;/p&gt;
&lt;p&gt;You could even try and be cheap and setup your own &lt;a href="https://louwrentius.com/blog/2009/07/20-disk-18-tb-raid-6-storage-based-on-debian-linux/"&gt;homegrown storage box&lt;/a&gt;es. 
It may not have all the cool features of a true SAN, but at least you have redundant storage. &lt;/p&gt;
&lt;p&gt;I'm really curious about this feature and I hope it works well. I'm seriously considering deploying this for the VMware setup of the company I currently work for. It does however require an extra external host that manages the actual replication, which may add to the cost. &lt;/p&gt;
&lt;p&gt;Any comments are welcome. &lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Why I bought a digital projector (Panasonic PT-AT5000E)</title><link href="https://louwrentius.com/why-i-bought-a-digital-projector-panasonic-pt-at5000e.html" rel="alternate"/><published>2012-10-21T00:00:00+02:00</published><updated>2012-10-21T00:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2012-10-21:/why-i-bought-a-digital-projector-panasonic-pt-at5000e.html</id><summary type="html">&lt;p&gt;I don't have a TV. I haven't been watching TV for more than 10 years. But I love to watch movies or great series like Dexter and Game of Thrones. Until recently, I watched movies or series on my 27" iMac. Twenty-seven inch is large for a computer screen but …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I don't have a TV. I haven't been watching TV for more than 10 years. But I love to watch movies or great series like Dexter and Game of Thrones. Until recently, I watched movies or series on my 27" iMac. Twenty-seven inch is large for a computer screen but for a TV, it's quite small.&lt;/p&gt;
&lt;p&gt;&lt;img alt="home setup" src="https://louwrentius.com/static/images/setup-01-sm-sm.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;When it comes to watching movies, a bigger screen is always better. The big screen of a movie theater is the most important reason for movie enthousiasts to experience a movie in the theatre. But there is a way to get that movie theatre feel into your living room: get a digital projector. That's what I did.&lt;/p&gt;
&lt;p&gt;I decided to get a ceiling mounted projection screen that I could lower just in front of my computer and table. I chose the "celexon Rollo Economy with a dimension of 277 x 156 cm (109 x 61 inch). This would give me a TV screen with a theoretical size of &lt;em&gt;125 inch&lt;/em&gt; in diameter! In practice, the actual projected image is around 120 inch.&lt;/p&gt;
&lt;p&gt;Just think about that. A 120 inch television. Hundred-and-twenty inch. Three metres diagonal. &lt;/p&gt;
&lt;p&gt;&lt;img alt="screen retracted" src="https://louwrentius.com/static/images/projectionscreen01.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;The screen can be lowered by just pulling on the edge. I have to reach for it on my toes but it's ok. As pictured below, the screen has an additional black area  so it can be lowered further away from the ceiling. This way, the effect of the ceiling reflecting light back to the screen, reducing picture quality, is reduced. It allows you to have the screen at the desired hight, you don't need to look up.&lt;/p&gt;
&lt;p&gt;&lt;img alt="screen retracted" src="https://louwrentius.com/static/images/projectionscreen02.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;At the other end of the room, I decided to mount a projector on a ceiling mount. My iMac would sent all digital content through a long HDMI cable to the projector. &lt;/p&gt;
&lt;p&gt;After doing some research I decided to buy the &lt;a href="http://www.panasonic.co.uk/html/en_GB/Products/Home+Entertainment/Projectors/PT-AT5000E/Overview/8073212/index.html"&gt;Panasonic PT-AT5000E&lt;/a&gt; also known as the PT-AE7000. This digital projector supports Full HD 1080p at 1920x1080. It also supports 3D but I'm not really interested in that. &lt;/p&gt;
&lt;p&gt;&lt;img alt="projector" src="https://louwrentius.com/static/images/panasonicprojector.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;I have never seen a movie on a digital projector before and I can't compare it to other digital projectors. But one thing is sure. Watching a 1080p movie on a 120" display projected by this digital projector is quite an experience. To me the picture is astounding. It is almost if you are in a theatre. A digital projector may not always be practical, but it is surely awesome. &lt;/p&gt;
&lt;p&gt;I do have some remarks about the whole setup with a digital projector:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;you need a big screen and mount it somewhere;&lt;/li&gt;
&lt;li&gt;the projector is just gigantic and you must accept that it hangs from your ceiling somewhere, something your spouse may not like;&lt;/li&gt;
&lt;li&gt;you need to run some extra cables for power and HDMI through your house;&lt;/li&gt;
&lt;li&gt;you need to put the lens cap on when the device is not in use, often a hassle;&lt;/li&gt;
&lt;li&gt;the lamp takes several minutes to reach optimal operational temperature;&lt;/li&gt;
&lt;li&gt;although my panasonic projector is almost silent, it does make noise;&lt;/li&gt;
&lt;li&gt;you must have good curtains to block all external light or you won't see a thing;&lt;/li&gt;
&lt;li&gt;you need to wait for movies to be released on Blu-ray or the Internet to be able to watch them;&lt;/li&gt;
&lt;li&gt;the lamp will wear out and replacements are expensive;&lt;/li&gt;
&lt;li&gt;if anyone would ask you about the size of your TV you would have to lie or feel a douchebag for telling the truth. &lt;/li&gt;
&lt;li&gt;Non-HD content looks totally crap and you need to make the picture smaller just to stand it.&lt;/li&gt;
&lt;li&gt;the whole home theatre setup is just expensive and you could have bought a lot of theatre tickets for that money;&lt;/li&gt;
&lt;li&gt;black levels are often not as good as plasma TV's.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;But in the end I would not hesitate to fork out the money for a home theatre setup like this. Because of the downside of movie theatres:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;other people. They are the cause that you don't have the best seat in front of the screen;&lt;/li&gt;
&lt;li&gt;more other people, who text, talk or phone during the movie; &lt;/li&gt;
&lt;li&gt;even more other people, who eat crappy food, making noise and drink crappy liquids as if it where a slurping contest;&lt;/li&gt;
&lt;li&gt;you need to pay money;&lt;/li&gt;
&lt;li&gt;you need to sit in some crappy movie theatre chair;&lt;/li&gt;
&lt;li&gt;you must pay top dollar for a drink or food;&lt;/li&gt;
&lt;li&gt;no pauses so no toilet breaks; &lt;/li&gt;
&lt;li&gt;you need to go there, and be there at a specific time;&lt;/li&gt;
&lt;li&gt;you need to stand many commercials before the movie actually starts;&lt;/li&gt;
&lt;li&gt;the sound quality is often horrible.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;So in my opinion, if you you are willing to spend money on it, I would advice to seriously look into getting a digital projector. &lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Compiling Multicore PAR2 on Ubuntu 12.04 LTS Precise Pangolin</title><link href="https://louwrentius.com/compiling-multicore-par2-on-ubuntu-1204-lts-precise-pangolin.html" rel="alternate"/><published>2012-09-16T01:00:00+02:00</published><updated>2012-09-16T01:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2012-09-16:/compiling-multicore-par2-on-ubuntu-1204-lts-precise-pangolin.html</id><summary type="html">&lt;p&gt;If you want to compile PAR2 with multicore support on Linux, it may not work right away from source. I used &lt;a href="http://www.chuchusoft.com/par2_tbb/download.html"&gt;this version of PAR2 with multicore support&lt;/a&gt;.
Update 2015: the original link is dead, I foud a copy of the source and put it on my own site &lt;a href="https://louwrentius.com/files/par2cmdline-0.4-tbb-20100203.tar.gz"&gt;here …&lt;/a&gt;&lt;/p&gt;</summary><content type="html">&lt;p&gt;If you want to compile PAR2 with multicore support on Linux, it may not work right away from source. I used &lt;a href="http://www.chuchusoft.com/par2_tbb/download.html"&gt;this version of PAR2 with multicore support&lt;/a&gt;.
Update 2015: the original link is dead, I foud a copy of the source and put it on my own site &lt;a href="https://louwrentius.com/files/par2cmdline-0.4-tbb-20100203.tar.gz"&gt;here for you to download.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;First, make sure that you have these libraries on your system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;libtbb-dev
libaio-dev
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;According to &lt;a href="https://forums.sabnzbd.org/viewtopic.php?f=1&amp;amp;t=1220"&gt;this source&lt;/a&gt;, after downloading the source, you need to add this line:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;#include &amp;lt;backward/auto_ptr.h&amp;gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;To these files:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;par2cmdline.cpp
commandline.cpp
par2creator.cpp
par2repairer.cpp
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Then edit the Makefile and find the LDADD variable. Add the -lrt option like this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;LDADD = -lstdc++ -ltbb -lrt -L.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This did the trick for me and compiled the PAR2 source with multicore support.
Hope it helps somebody.&lt;/p&gt;
&lt;p&gt;If you want to use Multicore PAR2 with SABNZBD you need to go to the Config menu. Then select 'Special' and enable 'par2_multicore'. Save the changes. Then go to 'Switches' and enter '-t+' at the Extra PAR2 Parameters field. &lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Fully unattended deployment of Windows clients using limited resources</title><link href="https://louwrentius.com/fully-unattended-deployment-of-windows-clients-using-limited-resources.html" rel="alternate"/><published>2012-07-07T19:00:00+02:00</published><updated>2012-07-07T19:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2012-07-07:/fully-unattended-deployment-of-windows-clients-using-limited-resources.html</id><summary type="html">&lt;h3&gt;Introduction&lt;/h3&gt;
&lt;p&gt;Anyone who ever installed Windows on a computer by hand must have wished for a solution that automate this task. It's just waiting a lot and pressing a button now and then. But installing the operating system itself is only the beginning. Once installed, you need to apply service …&lt;/p&gt;</summary><content type="html">&lt;h3&gt;Introduction&lt;/h3&gt;
&lt;p&gt;Anyone who ever installed Windows on a computer by hand must have wished for a solution that automate this task. It's just waiting a lot and pressing a button now and then. But installing the operating system itself is only the beginning. Once installed, you need to apply service packs or at least about a hundred or more security updates. When finished, you need to install all additional software, like an office suite, PDF reader, anti-virus software and the like.&lt;/p&gt;
&lt;p&gt;So you need to install:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;the operating system&lt;/li&gt;
&lt;li&gt;applications &lt;/li&gt;
&lt;li&gt;security updates&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you do this all by hand, it will probably take at least half a day, if not even longer. This is a major problem, because sooner or later you may have to hire somebody full time to do just the computer deployments. Expect a high job turnover rate. You definitely want to automate this task, saving money on extra sysadmins but more importantly: &lt;em&gt;quality&lt;/em&gt;. &lt;/p&gt;
&lt;p&gt;Even if you have to install one computer every week, you must automate this process for the sole reason that if you don't, no two deployed computers are the same. People make mistakes, especially with boring, repetitive tasks. So automation improves quality and reduces the workload significantly. &lt;/p&gt;
&lt;p&gt;If you don't deploy your end-user computers through some kind of automation, you need to stop what you are doing right now and build such a solution. It's fundamental to provide good quality service to your users. &lt;/p&gt;
&lt;p&gt;It must be fully unattended or as unattended as possible. You may have to press a button to initiate the process at that start, but that must be all that is required to deploy a system. If during deployment, you need to touch the computer in order for it to continue deploying, you have a bug that needs to be fixed asap.&lt;/p&gt;
&lt;p&gt;So, in this post I want to show you that with minimal resources, you can create a fully unattended solution for Windows desktop systems. There are probably better ways to do this, but for me, this was enough. &lt;/p&gt;
&lt;h3&gt;Imaging versus automated deployment&lt;/h3&gt;
&lt;p&gt;It's very simple. Do not image. Do not use products like Norton Ghost or Clonezilla for system deployment. Imaging is not flexible. For every change, you need to create a new image. For every hardware model, you need to create a new image. Every program update requires a new image. Instead of installing computers by hand, you are maintaining images. It does not scale.&lt;/p&gt;
&lt;p&gt;Automated installations on the other hand do scale. They are dynamic. They just use whatever drivers they need during installation, as long as they are available. Just updating the installer of an application is sufficient to make sure that future deployments are up-to-date. Flexibility is key.&lt;/p&gt;
&lt;h3&gt;Solution overview&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Clients use &lt;a href="http://en.wikipedia.org/wiki/Preboot_Execution_Environment"&gt;PXE&lt;/a&gt; to boot from the network. They boot a special Windows Embedded kernel that bootstraps the Windows installation process. &lt;/li&gt;
&lt;li&gt;The operating system and drivers are installed.&lt;/li&gt;
&lt;li&gt;All company software is installed.&lt;/li&gt;
&lt;li&gt;All security patches are installed.&lt;/li&gt;
&lt;li&gt;When ready, a mail is sent to the sysadmins&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You will need:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A DHCP server&lt;/li&gt;
&lt;li&gt;A WDS server&lt;/li&gt;
&lt;li&gt;A KMS server and valid KMS licence&lt;/li&gt;
&lt;li&gt;Valid Windows 7 ISO for KMS installation&lt;/li&gt;
&lt;li&gt;An unattended configuration created with WAIK&lt;/li&gt;
&lt;li&gt;Driver packs for the various desktop an laptop models&lt;/li&gt;
&lt;li&gt;A domain account dedicated for deployment&lt;/li&gt;
&lt;li&gt;A list + executables of all software required for the client&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;About KMS and Windows licences&lt;/h3&gt;
&lt;p&gt;In a larger environment, with 25+ desktops and laptops, it becomes to cumbersome to type in the product licence key and activate the systems by hand. This does not scale. You need a Volume Licence agreement for Windows 7 or higher in order to be able to use a Key Management Server and a special ISO of Windows 7 that does not require a product key. Learn more about this in &lt;a href="https://louwrentius.com/blog/2012/06/understanding-windows-kms-and-mak-volume-license-activation/"&gt;this blogpost&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Windows Deployment services&lt;/h3&gt;
&lt;p&gt;The basis for automated deployment is &lt;a href="http://en.wikipedia.org/wiki/Windows_Deployment_Services"&gt;Windows Deployment Services&lt;/a&gt;. This software made available for free by Microsoft allows clients to PXE boot and perform unattended operating system installations.&lt;/p&gt;
&lt;p&gt;Unattended operating system installations are guided by XML files that describe the configuration for the operatings system. Such a configuration file is authored with the &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=5753"&gt;Windows Automated Installation Kit&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;WDS uses two images: a boot image and an install image. Because computers need drivers, you need to download and inject the drivers in the boot image. All major vendors supply special complete driver packages for you to download. Just download, extract and import. Create driver groups for every model, to orden your drivers.&lt;/p&gt;
&lt;p&gt;You may choose to install all drivers in one image. But that image can grow large and lengten the installation time. To resolve this, create separate boot images for different vendors and differentiate between model lines. This is not much work but it keeps the boot images small. This is not required.&lt;/p&gt;
&lt;h3&gt;Windows Automated Installation Kit&lt;/h3&gt;
&lt;p&gt;You need the WAIK to author the XML file used by WDS to configure the unattended installation. You must specify hard disk partitioning, some default settings and the like. This is also where you configure the command to run when the operating system installation has finished. This will start the software installation phase.&lt;/p&gt;
&lt;h3&gt;Automated silent software deployment&lt;/h3&gt;
&lt;p&gt;For software installation, I just go back to my MS-DOS 4.11 days and use a simple batch script that installs all software.&lt;/p&gt;
&lt;p&gt;Every product, such as Adobe Reader or Java, has an installation batch file. There is one main batch file that calls each program install batch file to install it and log the results for debugging.&lt;/p&gt;
&lt;p&gt;It is that simple. And it works perfectly. The most important task is to find out for each product how you can install it silently, without user intervention.
Fortunately, almost all products provide command line arguments for unattended installation. &lt;/p&gt;
&lt;p&gt;Software is installed by using a domain-based unprivileged user that uses autologon to logon to the system, with local administrative privileges. Once the installation is complete, local admin privileges are revoked.&lt;/p&gt;
&lt;h3&gt;Installing all security updates&lt;/h3&gt;
&lt;p&gt;This is the hard part. There are several problems. First, after you install all updates, more updates seem to be available after the next reboot. Furthermore, using Windows 7, a &lt;a href="http://marc.durdin.net/2012/02/further-analysis-on-trustedinstallerexe.html"&gt;memory leak&lt;/a&gt; causes the installation proces to take ages. &lt;/p&gt;
&lt;p&gt;The solution is to install smaller batches of patches, such as 30 or 40 at a time. You can use a &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa387102(v=vs.85).aspx"&gt;script&lt;/a&gt; for that as supplied by Microsoft. This script must be changed not to install all patches, but a fixed number at a time.&lt;/p&gt;
&lt;p&gt;So you need several reboots to install all patches and run the VBS update script several times. The WAIK provides an option for 'autologon'. So you can have a user account logon for like 5 times. After that, no autologon is performed ever again.&lt;/p&gt;
&lt;p&gt;So you place a special batch file in the startup folder of the autologon user that triggers the Windows update process every time the autologon is performed.
This is the last step of the installation.&lt;/p&gt;
&lt;p&gt;After five autologons, the system will boot to the logon screen and the system is done.&lt;/p&gt;
&lt;h3&gt;Additional resources&lt;/h3&gt;
&lt;p&gt;Large organisations may use &lt;a href="http://www.microsoft.com/nl-nl/server-cloud/system-center/operations-manager-2012.aspx"&gt;Microsoft System Center Operations Manager&lt;/a&gt; but I assume that such a solution has not been setup. I asume, that you are in an environment without any existing solution that may help you out.&lt;/p&gt;
&lt;p&gt;I would also investigate the &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=25175"&gt;Microsoft Deployment Toolkit 2012&lt;/a&gt;. Instead of tinkering with batch files and vbs scripts, this may help you also. However, it seems to focus on creating images or automate the task of creating images, rather than just automate the installation of a client. &lt;/p&gt;
&lt;h3&gt;Final thoughts&lt;/h3&gt;
&lt;p&gt;Please note that I had to research this solution within a few weeks, with lots of other things to do. It was just one project of many other projects. There may be better solutions to automate system deployments. Maybe the MDT is a better approach, but I haven't tested it (yet). The current setup is sufficient for now and it frees us to start other much needed projects.&lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Understanding Windows KMS and MAK volume license activation</title><link href="https://louwrentius.com/understanding-windows-kms-and-mak-volume-license-activation.html" rel="alternate"/><published>2012-06-09T21:00:00+02:00</published><updated>2012-06-09T21:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2012-06-09:/understanding-windows-kms-and-mak-volume-license-activation.html</id><summary type="html">&lt;h3&gt;Introduction&lt;/h3&gt;
&lt;p&gt;If you have to administer a large number of PCs running Windows, you will end up creating an automated deployment platform for your Windows clients. You may implement something like &lt;a href="http://technet.microsoft.com/en-us/library/cc770628(v=ws.10).aspx"&gt;Windows Deployment Services&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;I used WDS to create a fully automated installation of PCs. WDS can also be used …&lt;/p&gt;</summary><content type="html">&lt;h3&gt;Introduction&lt;/h3&gt;
&lt;p&gt;If you have to administer a large number of PCs running Windows, you will end up creating an automated deployment platform for your Windows clients. You may implement something like &lt;a href="http://technet.microsoft.com/en-us/library/cc770628(v=ws.10).aspx"&gt;Windows Deployment Services&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;I used WDS to create a fully automated installation of PCs. WDS can also be used for creating images, but using images doesn't scale as you need too much manual intervention with the devices themselves and you need to update images constantly.&lt;/p&gt;
&lt;p&gt;With WDS and some driver packs I can support as many different computer brands and models as I want with a single vanilla Windows 7 base image. All customization and automation is done with answer files using the &lt;a href="http://en.wikipedia.org/wiki/Windows_Automated_Installation_Kit"&gt;Windows Automated Installation Kit&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;When creating an automated deployment environment, one thing you definitely don't want to be doing is having to enter each individual Windows product key as found on the sticker somewhere on the chasis. You want a single key, embedded in the deployment image or script and run with that, or some other solution. Your goal must be to do away with manual product key input and activation.&lt;/p&gt;
&lt;p&gt;This is not a problem, but here we have to introduce the topic of licences, especially client licences such as Windows 7. There are only two flavors of Windows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Retail - this licence is most expensive but allows you to transfer it from one computer to the other one.&lt;/li&gt;
&lt;li&gt;OEM - this licence cost you less but is tied to that particular computer.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The important thing for a system administrator to know is this: when buying OEM, you do &lt;em&gt;not&lt;/em&gt; have rights to create disk images or do something similar with these computers. You cannot use Windows Deployment Services, You cannot use cloning tools or other solutions.&lt;/p&gt;
&lt;h3&gt;Volume licensing&lt;/h3&gt;
&lt;p&gt;Now it is time to talk about volume licensing. A volume licence is an &lt;em&gt;upgrade&lt;/em&gt; of a Retail or OEM license. So one thing is sure: you must order every computer with an OEM Windows licence, regardless of your plans. In addition, the volume licence, you have to buy separately, you gain 'reimaging rights'.&lt;/p&gt;
&lt;p&gt;Now comes the fun part. You only need one (1) Volume Licence for a specific product to be eligible to image or automatically deploy &lt;em&gt;all&lt;/em&gt; PCs running that particular operating system (32 bit or 64 bit doesn't matter). &lt;/p&gt;
&lt;h3&gt;KMS or MAK activation&lt;/h3&gt;
&lt;p&gt;With a volume licence, client's don't need to activate with Microsoft through the internet. For larger organisations, that would cause too much internet traffic. Instead, you use a local activation service within your network. You can either deploy a &lt;a href="http://technet.microsoft.com/library/ff793434.aspx"&gt;KMS (Key Management Service)&lt;/a&gt; or use the &lt;a href="http://technet.microsoft.com/en-US/library/ff793435.aspx"&gt;Volume Actication Management Tool (VAMT)&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Most people may want the KMS service. But a KMS service only starts to validate clients with 25 or more PCs. If you have less than that number of clients, you may resort to MAK validation.&lt;/p&gt;
&lt;p&gt;When choosing KMS activation, you install a KMS service on one of your Windows servers and that host will then act as an activation server within your organisation. Systems activated through the KMS must periodically revalidate themselves (as like every 6 months / 180 days). but how do the clients know that they should validate against your KMS? And which product key do you use?&lt;/p&gt;
&lt;p&gt;If you buy a volume licence, you will get access to a special ISO image of Windows 7, Vista Business or XP Professional. You also gain access to a special product key, a KMS product key. (Please note that you must by a volume licence for each operating system product version).&lt;/p&gt;
&lt;p&gt;You use this special KMS product key to activate the KMS server. This happens only once. So this one time, you activate the KMS server with Microsoft, after that, no communication occurs with clients or the KMS service with Microsoft.&lt;/p&gt;
&lt;p&gt;That special ISO image you got contains a special Windows version that &lt;em&gt;does not require a product key&lt;/em&gt;. Once a client is installed, it just searches your network for a KMS server through DNS and tries to activate against it. Once validated, clients stay validated as long as they get in contact twice a year (180 days) with your KMS service.&lt;/p&gt;
&lt;p&gt;If you have less than 25 PCs, you will use the &lt;a href="http://technet.microsoft.com/en-US/library/ff793435.aspx"&gt;MAK activation and the VAMT tool&lt;/a&gt;. Clients can either activate through Microsoft directly or through the VAMT tool. The VAMT tool collects activation requests within your network like a KMS, however, it does contact Microsoft to validate those activations. And there is a limited number of activations you are entitled to. This VAMT tool can cache activation requests so you can redeploy or re-image systems and reactivate them without seeing your activation limit getting reached. &lt;/p&gt;
&lt;p&gt;I hope this information was useful to you and if you've discovered a mistake, please comment.&lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Neato XV-15 / XV-11 Robotic Vacuum cleaner review</title><link href="https://louwrentius.com/neato-xv-15-xv-11-robotic-vacuum-cleaner-review.html" rel="alternate"/><published>2011-12-25T09:00:00+01:00</published><updated>2011-12-25T09:00:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-12-25:/neato-xv-15-xv-11-robotic-vacuum-cleaner-review.html</id><summary type="html">&lt;p&gt;Update 18 February 2012&lt;/p&gt;
&lt;p&gt;There is one problem. When the robot is not connected to the charger, the batteries are depleted very fast. Even if the batteries are not entirely depleted and the robot can still display the menu, the clock loses it's time. Every time the robot gets a …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Update 18 February 2012&lt;/p&gt;
&lt;p&gt;There is one problem. When the robot is not connected to the charger, the batteries are depleted very fast. Even if the batteries are not entirely depleted and the robot can still display the menu, the clock loses it's time. Every time the robot gets a too low charge, you have to set the date and the time, which is a bit of a hassle. This does not happen often though. The robot seems to be consistently operating properly. &lt;/p&gt;
&lt;p&gt;Update 1 March 2012&lt;/p&gt;
&lt;p&gt;It seems that the batteries have worsened so bad that the device cannot clean my living room without 3x recharging. I have to return the product for repair.
I had the device scheduled to clean every other day, about 4x per week. &lt;/p&gt;
&lt;p&gt;Update 20 March 2012&lt;/p&gt;
&lt;p&gt;I received a brand new device that is now charging. I hope this one will last longer.&lt;/p&gt;
&lt;p&gt;Update 23 March 2012&lt;/p&gt;
&lt;p&gt;It seems that the brand new robot is also flawed, it just goes nuts. Seems to be up-to-date regarding software, so have to return this one also. (read below!)&lt;/p&gt;
&lt;p&gt;Update 31 March 2012&lt;/p&gt;
&lt;p&gt;I did not return this device and did some additional cleaning cycles. All cylces where performed withouth problems. The device choked om some cloth and some cables I forgot to cleanup, but it does seem to operate properly. So I will keep it.&lt;/p&gt;
&lt;p&gt;Uodate 4 May 2012&lt;/p&gt;
&lt;p&gt;Still works like a charm. I'm currently very hapy with it. If the batteries hold up, this device is really worth the money.&lt;/p&gt;
&lt;p&gt;Uodate 8 June 2012&lt;/p&gt;
&lt;p&gt;I had some critical battery errors and contacted support. They asked me to
check if the batteries are connected properly. So I just pushed on the connectors to make sure they are firmly connected. After that, I didn't see
any more battery errors and the device is still cleaning like a charm.&lt;/p&gt;
&lt;p&gt;Original article:&lt;/p&gt;
&lt;p&gt;So I bought a robotic vacuum cleaner. The first question is 'why would you spend some serious money on such a device? On a toy?'. I have some rationalisations for buying this device, but honestly, one reason is that sometimes I just like to buy a new toy. Something to play with. Excuse me for being human. In this blog post I want to explain to you why I bought a Neato XV-15 and not another product.&lt;/p&gt;
&lt;p&gt;Now I did say that I have some rationalisations, so let's start. One rationalisation is that I hate vacuum cleaning. Since I have two cats, vacuum cleaning once a week may not be enough. And I'm not going to clean more frequently. So you can accept it or if you can spare a little dough, buy a robotic vacuum cleaner that cleans your house when you're not at home.&lt;/p&gt;
&lt;p&gt;So let's introduce the Neato XV-15.&lt;/p&gt;
&lt;h3&gt;The Neato XV-15 Vacuum cleaning robot&lt;/h3&gt;
&lt;p&gt;The XV-15 robot is made by &lt;a href="http://www.neatorobotics.com/"&gt;Neato Robotics&lt;/a&gt;, a young startup that seems to be started purely for this device. The company started with the XV-11 for the US market, and the XV-15 is identical except that it is meant for the European market. A new &lt;a href="http://www.engadget.com/2011/10/11/neatos-xv-12-robot-vacuum-cleans-your-floors-dressed-in-white-f/"&gt;XV-12&lt;/a&gt; has also been announced, which seems to be identical to the other two machines, except for the color (white).&lt;/p&gt;
&lt;p&gt;The robot automatically vacuums your house while you're away or minding your own business. I't can't do anything else, but not having to vacuum all the time is kinda cool, right?&lt;/p&gt;
&lt;p&gt;I bought the XV-15 in The Netherlands for 500 euros. The XV-11 can be had for around $400 excluding taxes or maybe even for less at Amazon. Not very cheap, but competitively priced compared to other robots on the market.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Neato XV-15" src="https://louwrentius.com/static/images/xv-15-01.png" /&gt;&lt;/p&gt;
&lt;h3&gt;How the robot works&lt;/h3&gt;
&lt;p&gt;The XV-15 has a rubber brush at the front that rotates quite fast and that brush scoops up the dirt. Just behind the rubber brush, a vacuum mouth is present. Anything sucked up through that mouth enters the dustbin. The actual vacuum motor is at the back of the dustbin, protected by the dust filter of the dustbin. The XV-15 is a true vacuum and Neato claims that vacuuming power is way stronger than any other robot on the market. Based on the noise, that may be true.&lt;/p&gt;
&lt;p&gt;On top of the XV-15 you can find an LCD screen for configuring the robot and the turret housing its special secret weapon: laser sight. This is the cool part. &lt;/p&gt;
&lt;p&gt;The XV-15 has a laser system mounted on top that allows the robot to locate objects and walls. It is capable of creating a map of its surroundings. Anything the laser can 'see' will be avoided. The robot will not bump into any objects it can see. This is in stark contrast to products like the iRobot Roomba, which just bumps into everything. The XV-15 does have a front bumper though, because anything below the laser turret cannot be seen. Thus the robot does bump into things occasionally but it does a hard job trying not to.&lt;/p&gt;
&lt;p&gt;The laser system is not just for preventing collisions with furniture. Being able to generate a map of your house allows the robot to clean your house in an efficient manner. Robots like the Roomba just randomly zigzag through your house. If you do that long enough, chances are high that most of your house gets cleaned, which it will. &lt;/p&gt;
&lt;p&gt;The XV-15 only covers each spot once, and thus is able to clean your house much faster. It first cleans the perimeter of a room, hugging the walls. It then cleans the room in straight lines, like a swimmer in a pool. It remembers where it has cleaned or not and will come back later to a spot if something (like humans or pets) was occupying an area that can now be cleaned. &lt;/p&gt;
&lt;p&gt;My living-room, kitchen and entrance are cleaned in 40 minutes. An area of 40 square meters or about 420 square feet.&lt;/p&gt;
&lt;object width="470" height="315"&gt;&lt;param name="movie" value="http://www.youtube.com/v/p2jvRKzQP0M?version=3&amp;amp;hl=en_US"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/p2jvRKzQP0M?version=3&amp;amp;hl=en_US" type="application/x-shockwave-flash" width="470" height="315" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;/object&gt;

&lt;p&gt;When you see the XV-15 doing it's job, you may tend to stare at it longer than you may want to. It's just fascinating to see the device effortlessly navigating around your house. And it doesn't need stuff like battery operated 'light houses' like the Roomba's need. It is truly autonomous except for emptying the dust bin.&lt;/p&gt;
&lt;p&gt;The XV-15 seems to divide the rooms it detects in parts and will start cleaning those parts one after another. As said earlier, the robot will continue cleaning where it had left off if the batteries are low and needs recharging.&lt;/p&gt;
&lt;p&gt;The robot has no problem detecting stairs. Neato has also provided a roll of magnetic strip that can be used as a boundary marker. The robot will not cross this strip and will clean around it.&lt;/p&gt;
&lt;p&gt;However, how smart the XV-15 may be, you need to make your house robot-proof. The first time you start cleaning with the Neato, it is advised to monitor it's progress and 'fix' difficult spots in your house. I have no experience with other robots, but I think that this is true for all of them.&lt;/p&gt;
&lt;p&gt;The robot is just low enough that it can clean underneath my central heating radiators, which is very nice. It also has no trouble cleaning under my bed, an area which seems to collect dust very fast.&lt;/p&gt;
&lt;p&gt;The robot has never had any problems finding the base. It gently wiggles it's behind towards the base until it has a connection. It then informs you with a sound that it has finished cleaning.&lt;/p&gt;
&lt;h3&gt;Docking station&lt;/h3&gt;
&lt;p&gt;The XV-15 comes with a docking station that allows the device to automatically recharge for the next run. The XV-15 will return to the docking station if the batteries are low. When recharged, the XV-15 will continue cleaning where it left off. If you have a single story apartment, the XV-15 will thus clean the entire apartment all by itself, even if it can't clean your home in one take on a single battery charge. After recharging, the unit will just return to the spot where it aborted cleaning to recharge and continue cleaning. &lt;/p&gt;
&lt;p&gt;&lt;img alt="Neato XV-15" src="https://louwrentius.com/static/images/xv-15-02.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;The docking station allows you to put excess power cord into the station itself, to keep cable clutter to a minimum. You can also reroute the cable to exit the station from either the left side or right side.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Neato XV-15" src="https://louwrentius.com/static/images/xv-15-04.jpg" /&gt;&lt;/p&gt;
&lt;h3&gt;Scheduling&lt;/h3&gt;
&lt;p&gt;The robot can start cleaning with a press of the big orange button. The robot will start cleaning and return to the docking station when finished. Ideally, you want to have the robot clean the house when you're not around. Fortunately you can set a schedule for all seven days of the week. &lt;/p&gt;
&lt;p&gt;The robot has a clear LCD screen with a very easy menu for setting the clock and entering a schedule. A few simple buttons allows you to enter a schedule, which probably has to be done once. I have it set to clean every other day except for the weekend. &lt;/p&gt;
&lt;p&gt;Scheduling is extremely simple: for all seven days of the week, you can configure a start time or choose not to clean that day. That's all.&lt;/p&gt;
&lt;h3&gt;Noise level&lt;/h3&gt;
&lt;p&gt;When you start the XV-15 for the first time, you will be surprised by the of noise this little device generates. The vacuum motor is loud, but the rubber brush adds an additional roaring and rattling sound to it that is just almost unbearable. &lt;/p&gt;
&lt;p&gt;The rubber brush keeps hitting the floor causing the loud rattling sound. I had to add some felt strips on the bottom to raise the robot a little bit from the ground. This eliminated the rattling, but the robot is very loud. Keep this in mind. &lt;/p&gt;
&lt;p&gt;I think the noise level is the biggest downside of this robot.&lt;/p&gt;
&lt;h3&gt;Cleaning performance&lt;/h3&gt;
&lt;p&gt;The picture shows what the XV-15 can collect during a sweep. I dit not perform any scientific tests to verify the cleaning performance of the robot, but any visible dirt is always devoured by the robot. I'm personally very pleased with the results.&lt;/p&gt;
&lt;p&gt;&lt;img alt="dirt" src="https://louwrentius.com/static/images/xv-15-06.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;I found a &lt;a href="http://www.robotsaldetalle.es/review/neato-xv-15/#prueba%20de%20eficiencia"&gt;source&lt;/a&gt; written in Italian that seems to suggest that the XV-15 does a significantly worse job of cleaning stuff (67%) than the Roomba 780 (97%) robot, but it is an artificial test that does not use the stuff it is supposed to clean: (fine) dust and hair. However, it thus may be possible that the dumb Roomba's clean better. I don't know. &lt;/p&gt;
&lt;p&gt;I only can tell you that even if you clean daily and you have some pets, you will find quite some stuff inside the dustbin after each run.&lt;/p&gt;
&lt;h3&gt;Maintenance&lt;/h3&gt;
&lt;p&gt;The iRobot Roomba range of products seem to require quite some maintenance. The biggest issue with the Roombas is the fact that you need to clean out hair from the bearings and brushes after each run. This is not necessary with the XV-15.&lt;/p&gt;
&lt;p&gt;I don't know how much time cleaning of a Roomba takes, but I have an issue with that: why bother with a robot if you have to clean the robot instead of the house itself? Yes cleaning the robot takes less time, but it's probably no fun either.&lt;/p&gt;
&lt;p&gt;The only thing that you need to do when the XV-15 is finished: empty the dustbin and clean the filter. That will take no longer than 30 seconds I guess. No need to clean up the brush or bearings. It is of course advised to inspect the brush and bearings now and then. &lt;/p&gt;
&lt;p&gt;&lt;img alt="XV-15" src="https://louwrentius.com/static/images/xv-15-05.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;Checking the condition of the rubber brush and bearings is very easy. The brush guard can be removed without tools in seconds. Removing the rubber brush is just as easy and cleaning the axles shouldn't take long if ever required. I've never had to clean the brush itself. It seems that hair gets sucked up and doesn't stick to the brush. &lt;/p&gt;
&lt;h3&gt;Inside the box&lt;/h3&gt;
&lt;p&gt;The XV-15 comes with an additional rubber brush and four additional filters. According to Neato, you need to replace the filter every three to six months, depending on the frequency of your cleaning schedule. At 16 euros ($20) for 4 filters, that's not a big deal I guess.&lt;/p&gt;
&lt;p&gt;I couldn't find any details on how long the rubber brush will last.&lt;/p&gt;
&lt;h3&gt;Updating the software&lt;/h3&gt;
&lt;p&gt;If you take a closer look at the back of the robot, you will notice that at the left side of the big exhaust vent, two small ports are present: for power (only useful if you do not use the docking station) and a USB port. The USB port can be used to update the software of the robot to the latest version.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Neato XV-15" src="https://louwrentius.com/static/images/xv-15-03.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;Please note that Neato does not suply a USB cable so you need to get a mini USB cable when you want to update the software (firmware) of the robot. Bad news for Apple and Linux users: the firmware update software only runs on Windows. You can update the robot from Windows running inside VMware (Workstation or Fusion).&lt;/p&gt;
&lt;p&gt;Take a look at &lt;a href="http://www.neatorobotics.com/support/neato-software-updates"&gt;Neato's update page&lt;/a&gt; to see if new updates are available.&lt;/p&gt;
&lt;h3&gt;Hacking the XV-15&lt;/h3&gt;
&lt;p&gt;When the robot is connected to the computer through USB, you can communicate with the device through Hyperterminal or Minicom. If you like hacking your robot, continue reading &lt;a href="http://random-workshop.blogspot.com/2010/12/communicating-with-xv-11.html"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Conclusion&lt;/h3&gt;
&lt;p&gt;I'm quite happy with the robot. The biggest question is how long this device will last. At first, a robot like this seems a bit as a toy and it may be, but it is a pretty darn useful one. &lt;/p&gt;
&lt;p&gt;The lack of maintenance compared to the other robots is a big plus to me. If you have to spend time on cleaning the robot itself, where is the benefit?&lt;/p&gt;
&lt;p&gt;To me, the only downside is the noise. &lt;/p&gt;
&lt;p&gt;It can't vacuum the stairs. It can't vacuum in every corner. But the device can clean the majority of your house more often than you would probably have done yourself.&lt;/p&gt;
&lt;h3&gt;Additional sources&lt;/h3&gt;
&lt;p&gt;&lt;a href="http://www.robotreviews.com/chat/viewforum.php?f=20&amp;amp;sid=31179a9933b98c277efe8e0b049a4c25"&gt;Robot Reviews&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Very cool &lt;a href="http://www.youtube.com/watch?v=g8gDB08rnGE&amp;amp;feature=related"&gt;youtube film&lt;/a&gt; showing the robot through 'near infrared' view.&lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Lion's FileVault does not support Bootcamp and external boot disks</title><link href="https://louwrentius.com/lions-filevault-does-not-support-bootcamp-and-external-boot-disks.html" rel="alternate"/><published>2011-08-05T01:00:00+02:00</published><updated>2011-08-05T01:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-08-05:/lions-filevault-does-not-support-bootcamp-and-external-boot-disks.html</id><summary type="html">&lt;p&gt;&lt;strong&gt;Read the comments as they may provide useful information for your particular situation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I boot my iMac from an external FW800 SSD. I found out that it is impossible to
encrypt this disk using the new FileVault as part of Lion.&lt;/p&gt;
&lt;p&gt;&lt;img alt="no filevault" src="https://louwrentius.com/static/images/nofv.png" /&gt;&lt;/p&gt;
&lt;p&gt;Furthermore, I also found out that if you have …&lt;/p&gt;</summary><content type="html">&lt;p&gt;&lt;strong&gt;Read the comments as they may provide useful information for your particular situation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I boot my iMac from an external FW800 SSD. I found out that it is impossible to
encrypt this disk using the new FileVault as part of Lion.&lt;/p&gt;
&lt;p&gt;&lt;img alt="no filevault" src="https://louwrentius.com/static/images/nofv.png" /&gt;&lt;/p&gt;
&lt;p&gt;Furthermore, I also found out that if you have a disk with a Bootcamp partition
FileVault will also refuse to start the encryption process. I'm not trying to 
encrypt the Bootcamp volume, just the bootable Mac OS X Lion installation.&lt;/p&gt;
&lt;p&gt;&lt;img alt="no encryption with bootcamp" src="https://louwrentius.com/static/images/nobootcampfv.png" /&gt;&lt;/p&gt;
&lt;p&gt;It may be advised to stay away from Lion if you need a setup similar to this one 
and also need disk encryption. &lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Lion's Disk Utility not compatible with CoreStorage and Filevault</title><link href="https://louwrentius.com/lions-disk-utility-not-compatible-with-corestorage-and-filevault.html" rel="alternate"/><published>2011-08-03T00:00:00+02:00</published><updated>2011-08-03T00:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-08-03:/lions-disk-utility-not-compatible-with-corestorage-and-filevault.html</id><summary type="html">&lt;p&gt;My 1 TB hard drive of my 2011 27" iMac was partitioned with:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A bootable partition with Mac OS X Lion&lt;/li&gt;
&lt;li&gt;Time machine partition (I use an external SSD as my main OS)&lt;/li&gt;
&lt;li&gt;Bootcamp partition with windows&lt;/li&gt;
&lt;li&gt;A data partition containg... data.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The problem is that CoreStorage is too new …&lt;/p&gt;</summary><content type="html">&lt;p&gt;My 1 TB hard drive of my 2011 27" iMac was partitioned with:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A bootable partition with Mac OS X Lion&lt;/li&gt;
&lt;li&gt;Time machine partition (I use an external SSD as my main OS)&lt;/li&gt;
&lt;li&gt;Bootcamp partition with windows&lt;/li&gt;
&lt;li&gt;A data partition containg... data.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The problem is that CoreStorage is too new. Disk Utility in Lion cannot cope with CoreStorage volumes. So when I decided to encrypt the bootable partition using the new Full Disk Encryption based on filevault, I could no longer manage my other partitions.  &lt;/p&gt;
&lt;p&gt;&lt;img alt="disk utility" src="https://louwrentius.com/static/images/du01.png" /&gt;&lt;/p&gt;
&lt;p&gt;Furthermore, bootcamp got killed since it needs to be installed on one of the first three partitions on the disk. Due to the whole CoreStorage stuff and filevault, it became the fifth partition and it got killed. I couldn't get it back to life It wouldn't boot.&lt;/p&gt;
&lt;p&gt;What I want now is to create a setup where I have three partitions:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A bootable (Boot) clone of my external FW800 SSD boot disk using SuperDuper&lt;/li&gt;
&lt;li&gt;A Bootcamp volume running Windows (for games)&lt;/li&gt;
&lt;li&gt;A data partition storing well.. data.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;I want to encrypt the boot disk and the data partition. If this is going to work, I don't know. &lt;/p&gt;
&lt;p&gt;It may be advised to stay away from Lion if you need a setup similar to this one and also need disk encryption. &lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Additional proof that Apple is ditching the optical drive</title><link href="https://louwrentius.com/additional-proof-that-apple-is-ditching-the-optical-drive.html" rel="alternate"/><published>2011-07-23T15:00:00+02:00</published><updated>2011-07-23T15:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-07-23:/additional-proof-that-apple-is-ditching-the-optical-drive.html</id><summary type="html">&lt;p&gt;I'm a &lt;a href="https://louwrentius.com/blog/2009/10/blu-ray-is-dead/"&gt;strong advocate&lt;/a&gt; of &lt;a href="https://louwrentius.com/blog/2010/10/apple-is-killing-off-the-optical-drive-just-like-the-floppy-disk/"&gt;killing the optical drive&lt;/a&gt;. As of 2011, there is no need for it anymore. Laptops could get lighter, smaller or have more room for additional battery capacity if the optical drive would no longer be present.&lt;/p&gt;
&lt;p&gt;In my life, I never see people use the …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I'm a &lt;a href="https://louwrentius.com/blog/2009/10/blu-ray-is-dead/"&gt;strong advocate&lt;/a&gt; of &lt;a href="https://louwrentius.com/blog/2010/10/apple-is-killing-off-the-optical-drive-just-like-the-floppy-disk/"&gt;killing the optical drive&lt;/a&gt;. As of 2011, there is no need for it anymore. Laptops could get lighter, smaller or have more room for additional battery capacity if the optical drive would no longer be present.&lt;/p&gt;
&lt;p&gt;In my life, I never see people use the optical drive. And why would you use them any more? Isn't it so that if you are still using CDs or DVDs with your computer, that you do it out of (a bad) habit? And if you really can't part with your CDs or DVDs, would an external USB optical drive be a usable solution? &lt;/p&gt;
&lt;p&gt;I think that we are at a point where most people don't even know that their computer has an optical drive. &lt;/p&gt;
&lt;p&gt;With the release of the new 2011 Mac Mini, Apple dropped the optical drive yet again. They first dropped it from the MacBook Air and now the Mini. &lt;/p&gt;
&lt;p&gt;What is next? Well that is clear. New Macs &lt;a href="http://support.apple.com/kb/HT4718"&gt;will be able to boot over the Internet&lt;/a&gt; from Apple's servers. Again, no need for an optical drive, even for reinstalling your computer. I wouldn't be surprised if the next generation of MacBook Pro laptops would not contain an optical drive. Maybe some people aren't ready for it but people should rejoice since it would make MacBooks thinner and lighter.&lt;/p&gt;
&lt;p&gt;As apple killed the floppy drive, it is now killing the optical drive. &lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Cannot access Windows guest within VMware Fusion when running vsphere client</title><link href="https://louwrentius.com/cannot-access-windows-guest-within-vmware-fusion-when-running-vsphere-client.html" rel="alternate"/><published>2011-06-17T09:00:00+02:00</published><updated>2011-06-17T09:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-06-17:/cannot-access-windows-guest-within-vmware-fusion-when-running-vsphere-client.html</id><summary type="html">&lt;p&gt;Currently, I am running VMware ESXi 4.1 on a test system. To manage ESXi, you need the VSphere client, which is only available for the Windows platform. Therefore, I run VMware Fusion on my Mac to be able to access VSphere and manage my ESXi host. &lt;/p&gt;
&lt;p&gt;The trouble is …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Currently, I am running VMware ESXi 4.1 on a test system. To manage ESXi, you need the VSphere client, which is only available for the Windows platform. Therefore, I run VMware Fusion on my Mac to be able to access VSphere and manage my ESXi host. &lt;/p&gt;
&lt;p&gt;The trouble is that both ESXi and VMware Fusion use the control-alt shortcut to release a console. So as soon as you start using a console within the VSphere client which itself runs within VMware Fusion, you cannot get back to the Windows OS. &lt;/p&gt;
&lt;p&gt;You will have either access to Mac OS X or the ESXi guest. And to top it of, the mouse just completely disappears on Windows. &lt;/p&gt;
&lt;p&gt;To get arount this problem, you need to somehow be able to send a control-alt sequence to the Windows guest withouth actually pressing control-alt. &lt;/p&gt;
&lt;p&gt;Fortunately, VMware fusion allows you to create a key mapping that allows this. &lt;/p&gt;
&lt;p&gt;Within the preferance pane, the first tab is called Key Mappings. You can create a new key mapping. For example, I mapped control+q to control-alt. This allows me to get out of the ESXi guest within the VSphere client, witouth getting grown back to Mac OS X. As a side effect, the mouse also showed up again, which is to be expected.&lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Determining smartphone market share using wireless sniffing</title><link href="https://louwrentius.com/determining-smartphone-market-share-using-wireless-sniffing.html" rel="alternate"/><published>2011-04-24T23:00:00+02:00</published><updated>2011-04-24T23:00:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-04-24:/determining-smartphone-market-share-using-wireless-sniffing.html</id><summary type="html">&lt;p&gt;I started a project to see if I could track smartphone users by sniffing for
wifi-clients. Most smartphones support wifi and most people don't bother disabling
wifi when they go outdoors&lt;a href="http://www.aircrack-ng.org/doku.php?id=airmon-ng"&gt;1&lt;/a&gt;. If wifi is left on, it is possible to detect these
smartphones and track their movement. To be …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I started a project to see if I could track smartphone users by sniffing for
wifi-clients. Most smartphones support wifi and most people don't bother disabling
wifi when they go outdoors&lt;a href="http://www.aircrack-ng.org/doku.php?id=airmon-ng"&gt;1&lt;/a&gt;. If wifi is left on, it is possible to detect these
smartphones and track their movement. To be able to track smartphones, all I had
to do is grab a computer with a wifi card and start to listen for nearby
smartphones.&lt;/p&gt;
&lt;p&gt;Over de course of 10 days I was able to detect around 590 unique wireless client
devices passing the vicinity of my house (near Amsterdam, The Netherlands). 
Please note that not all of those devices are smartphones, so I have to 
determine which are and which are not. I just used &lt;a href="http://www.aircrack-ng.org/doku.php?id=airmon-ng"&gt;airmon-ng&lt;/a&gt; to sniff 
for wifi clients.&lt;/p&gt;
&lt;p&gt;It is very easy to track a person if wifi is enabled on their smartphone since
the phone will broadcast its unique identifier: its MAC-address. A MAC-address 
is as unique as a phone number so ideal for tracking down people. A single wifi
sniffing computer is not enough to follow people, but if you would setup a grid
of wifi sniffing devices, tracking people would be very easy. &lt;/p&gt;
&lt;p&gt;Then I got bored with this project and decided that if I could get any additional
information out of my data set of 590 wifi clients. The fun thing is that the
first tree parts of a MAC-address disclose the vendor of the device. For
instance, this MAC-address (made anonymous) belongs to HTC, thus is probably an 
HTC smartphone.&lt;/p&gt;
&lt;p&gt;90:27:E4:B7:XX:XX&lt;/p&gt;
&lt;p&gt;There is a whole &lt;a href="http://standards.ieee.org/develop/regauth/oui/oui.txt"&gt;list&lt;/a&gt; that shows which MAC-addresses belong to which
manufacturers. This allows me to create a list of vendors associated with the
MAC-addresses I captured. This is fun, because I can now count how many devices
I 'caught' from a particular vendor. &lt;/p&gt;
&lt;p&gt;The majority of wireless devices are from Apple (64%). The second largest is HTC
(12%). That is an incredible difference between number one and number two. If
these numbers actually mean anything, they are very interesting.&lt;/p&gt;
&lt;p&gt;&lt;img alt="smartphoneshare" src="https://louwrentius.com/static/images/smartphonewifisniffing01.png" /&gt;&lt;/p&gt;
&lt;p&gt;I think this picture is telling, but it's accuracy can be questioned. There are
some problems with my data set. For instance, maybe many people using a
particular brand of smartphone who do often disable wifi to conserve battery
life. &lt;/p&gt;
&lt;p&gt;Also, look whose missing in this list: Sony Ericsson. Are Dutch people not
using Sony Ericsson smartphones? I must say that I deliberately used a Sony
Ericsson smartphone to test my setup and it detected the device without any
problem. So Sony Ericsson devices might not be that popular.&lt;/p&gt;
&lt;p&gt;The main question is which conclusions can be drawn from this data: that iOS
users often leave their wifi enabled and more than other smartphone users?&lt;/p&gt;
&lt;p&gt;It is difficult to say what this data actually means and how accurate it is, but
it may be an interesting technique none the less for real-life sampling of a
smartphone population.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;a href="http://www.aircrack-ng.org/doku.php?id=airmon-ng"&gt;1&lt;/a&gt; Unless your phone is so crappy that it won't hold a charge through the day with wifi enabled.&lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Setting up a Jabber instant messaging server |_http-title: Site doesn't have a title (text/html; charset=utf-8).</title><link href="https://louwrentius.com/setting-up-a-jabber-instant-messaging-server-_http-title-site-doesnt-have-a-title-texthtml-charsetutf-8.html" rel="alternate"/><published>2011-02-05T22:00:00+01:00</published><updated>2011-02-05T22:00:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-02-05:/setting-up-a-jabber-instant-messaging-server-_http-title-site-doesnt-have-a-title-texthtml-charsetutf-8.html</id><summary type="html">&lt;p&gt;I wanted to see how dificult it is to setup an instant messaging server based on open source software. Now I know that it is &lt;em&gt;very&lt;/em&gt; easy, unless you are stubborn and do things your own way. In this example, I'm setting up a small IM server that is only …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I wanted to see how dificult it is to setup an instant messaging server based on open source software. Now I know that it is &lt;em&gt;very&lt;/em&gt; easy, unless you are stubborn and do things your own way. In this example, I'm setting up a small IM server that is only for internal company use, but there is no difference if you want to expose the server to the internet.&lt;/p&gt;
&lt;p&gt;First a bit background information. There is an open IETF standard for instant messaging called "XMPP" which stands for "Extensible Messaging and Presence Protocol". This protocol originated as part of the open source Jabber IM server software.&lt;/p&gt;
&lt;h3&gt;Setting up ejabberd&lt;/h3&gt;
&lt;p&gt;I decided to use &lt;a href="http://www.ejabberd.im/"&gt;ejabberd&lt;/a&gt; which is part of the Debian software archive. It is written in Erlang, but I can live with that. This blog posts documents how to setup the IM server with two accounts that can chat with each other. The configuration I use also enforces the use of SSL/TLS so authentication and all messages are encrypted.&lt;/p&gt;
&lt;p&gt;Steps to get things running:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;apt-get update&lt;/li&gt;
&lt;li&gt;apt-get install ejabberd&lt;/li&gt;
&lt;li&gt;cd /etc/ejabberd&lt;/li&gt;
&lt;li&gt;edit ejabberd.cfg&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Change the following line to your needs: &lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="c"&gt;%% Hostname&lt;/span&gt;
&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="n"&gt;hosts&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;localhost&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s"&gt;&amp;quot;jabber.domain.local&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;]}.&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Also enforce the use of encryption like this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;starttls, {certfile, &amp;quot;/etc/ejabberd/ejabberd.pem&amp;quot;}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Must be changed to:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;starttls_required, {certfile, &amp;quot;/etc/ejabberd/server.pem&amp;quot;}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h3&gt;Generating a custom SSL certificate&lt;/h3&gt;
&lt;p&gt;Security wise, it is &lt;em&gt;very&lt;/em&gt; wrong to use the default SSL certificate as provided by the installation package for the server certificate. Anyone with access to this key material can decrypt encrypted communication. So you must generate your own server certificate. This is also required because IM clients may verifiy the certificate against the domain name used within the certificate. If there is no match, it will not work or it will at least complain.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;openssl req -new -x509 -newkey rsa:2048 -days 365 -keyout privkey.pem \ 
-out server.pem
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;So this creates a public key (server.pem) and a private key (privkey.pem) which are valid for a year. Feel free to make the certificate valid for a longer period, this is an example. You will have to fill in some stuff, the most important part is this part:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;Common Name (eg, YOUR name) []:jabber.domain.local
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;You are forced to set a password on the private key, but we want to remove this because otherwise the ejabberd service will not start automatically. &lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;openssl rsa -in privkey.pem -out privkey.pem
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Just enter the password you entered earlier and you're done. We now have separate files for the public and private key, but ejabberd expects them in one single file. &lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;cat privkey.pem &amp;gt;&amp;gt; server.pem
rm privkey.pem
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Set proper file system permissions:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;chown ejabberd server.pem
chmod 600 server.pem
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Now we are done. Restart ejabberd to use the new settings.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;/etc/init.d/ejabberd restart
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h3&gt;Security caveats&lt;/h3&gt;
&lt;p&gt;Please note that the ejabberd daemon provides a small build-in web interface for administration purposes on TCP port 5280. By default it is not protected by SSL or TLS and cannot be used unless you add users to this part of the confiuration file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;{acl, admin, {user, &amp;quot;&amp;quot;, &amp;quot;localhost&amp;quot;}}.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Example:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;{acl, admin, {user, &amp;quot;admin&amp;quot;, &amp;quot;localhost&amp;quot;}}.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The user must also be registered as a normal IM user as described in the next section.&lt;/p&gt;
&lt;p&gt;Warning: it seems to me that this interface is not very secure, for example, there is no logout button. &lt;/p&gt;
&lt;p&gt;Furthermore, you might consider disabling the following section:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;ejabberd_s2s_in
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This prevents your IM server from communicating with other IM servers &lt;a href="http://www.ejabberd.im/disable-s2s"&gt;source&lt;/a&gt;. But we are not finished. When you install ejabberd, some other services are also started on the system. It is thus very important that you configure your firewall to block these ports. This small nmap port scan output shows some interesting services:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="mf"&gt;4369&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tcp&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="kr"&gt;open&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;epmd&lt;/span&gt;&lt;span class="err"&gt;?&lt;/span&gt;
&lt;span class="mf"&gt;5222&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tcp&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="kr"&gt;open&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;jabber&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;ejabberd&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Protocol&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;1.0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="mf"&gt;5269&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tcp&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="kr"&gt;open&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;jabber&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;ejabberd&lt;/span&gt;
&lt;span class="mf"&gt;5280&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tcp&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="kr"&gt;open&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="n"&gt;ejabberd&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;admin&lt;/span&gt;
&lt;span class="err"&gt;|&lt;/span&gt;&lt;span class="n"&gt;_http&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;methods&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;No&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Allow&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="ow"&gt;or&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Public&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;header&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;in&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;OPTIONS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;response&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;status&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;code&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;400&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="mf"&gt;36784&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tcp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kr"&gt;open&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;unknown&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Port 4369, 36784 and 5280 should be blocked by your firewall and not accessible from the internet.&lt;/p&gt;
&lt;h3&gt;Adding users&lt;/h3&gt;
&lt;p&gt;It is now time to create some IM users. A user account always looks like an email addres, for example:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;peter&lt;/span&gt;&lt;span class="nv"&gt;@jabber&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;local&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;To add accounts, use the ejabberdctl utiliy:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;ejabberdctl&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;register&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;peter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;jabber&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;local&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Please note that passwords that are entered on the command line end up in your bash_history file, so beware. Also, users running ps aux may be able to see the command for a brief moment. So be carefull.&lt;/p&gt;
&lt;p&gt;By registering two account, you can test your new server. &lt;/p&gt;
&lt;h3&gt;Additional resources&lt;/h3&gt;
&lt;p&gt;Nice to know: the domain names used for your accounts can differ from the domain used for the IM server.&lt;/p&gt;
&lt;p&gt;If you have a Windows Active Directory domain, you could consider authenticating your users against LDAP.&lt;/p&gt;
&lt;p&gt;Other resources:
- &lt;a href="http://www.ejabberd.im/tuto-install-ejabberd"&gt;tutorial 1&lt;/a&gt;
- &lt;a href="http://sysmonblog.co.uk/2008/06/ot-installing-ejabberd-on-debian-ubuntu.html"&gt;tutorial 2&lt;/a&gt;&lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>'Improved' image gallery for Blogofile</title><link href="https://louwrentius.com/improved-image-gallery-for-blogofile.html" rel="alternate"/><published>2011-01-21T22:47:00+01:00</published><updated>2011-01-21T22:47:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-01-21:/improved-image-gallery-for-blogofile.html</id><summary type="html">&lt;p&gt;This blog is just static HTML pages that are generated using &lt;a href="http://blogofile.com"&gt;Blogofile&lt;/a&gt;. The Blogofile website sports a small image gallery that has been written to illustrate how to create your own 'controllers' or Blogofile plugins. &lt;/p&gt;
&lt;p&gt;My Python skills are horrible buy I managed to improve a bit on this example …&lt;/p&gt;</summary><content type="html">&lt;p&gt;This blog is just static HTML pages that are generated using &lt;a href="http://blogofile.com"&gt;Blogofile&lt;/a&gt;. The Blogofile website sports a small image gallery that has been written to illustrate how to create your own 'controllers' or Blogofile plugins. &lt;/p&gt;
&lt;p&gt;My Python skills are horrible buy I managed to improve a bit on this example photo gallery. If you click on the '&lt;a href="/pictures"&gt;Photos&lt;/a&gt;' menu at the top of this blog, you can see an example of the result.  &lt;/p&gt;
&lt;h3&gt;What is the improvement?&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Basically one thing: it create a gallery by traversing recursively over a directory structure containing pictures. &lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;How to install?&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Just create a folder where you will store pictures. &lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Add this to your _config.py&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;code&gt;photo_gallery = controllers.photo_gallery&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;photo_gallery.enabled = True&lt;/code&gt; &lt;/p&gt;
&lt;p&gt;&lt;code&gt;photo_gallery.path = "pictures"&lt;/code&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;put &lt;a href="/files/photo_gallery.py"&gt;this file&lt;/a&gt; into _controllers/photo_gallery&lt;/li&gt;
&lt;li&gt;enter into this gallery and create a symlink like:&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;code&gt;ln -s photo_gallery.py __init__.py&lt;/code&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;download the example templates &lt;a href="/files/photo-templates.tgz"&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Additional info&lt;/h3&gt;
&lt;p&gt;This photo gallery generator ignores symlinks. However, it looks for a special file name in every directory:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;showcase.jpg
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This file can be a symnlink to one of the photo's. It is used as the identifying picture for a folder with pictures. Every directory should contain at least a single showcase.jpg.&lt;/p&gt;
&lt;p&gt;If you have a folder called Europe containing two sub folders England and France, you can create a showcase.jpg symlink to one of the underlying showcase files of one of the folders. This picture will then be used to 'identify' the "Europe" folder.&lt;/p&gt;
&lt;p&gt;Example directory tree:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;./Europe
./Europe/England
./Europe/England/London
./Europe/England/London/showcase.jpg
./Europe/England/showcase.jpg
./Europe/France
./Europe/France/Nice
./Europe/France/Nice/showcase.jpg
./Europe/France/showcase.jpg
./Europe/Netherlands
./Europe/Netherlands/Enkhuizen
./Europe/Netherlands/Enkhuizen/showcase.jpg
./Europe/Netherlands/showcase.jpg
./Europe/showcase.jpg
./USA
./USA/New York
./USA/New York/showcase.jpg
./USA/showcase.jpg
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content><category term="Uncategorized"/></entry><entry><title>Migration from blogger to blogofile and disqus is complete</title><link href="https://louwrentius.com/migration-from-blogger-to-blogofile-and-disqus-is-complete.html" rel="alternate"/><published>2011-01-04T00:58:00+01:00</published><updated>2011-01-04T00:58:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2011-01-04:/migration-from-blogger-to-blogofile-and-disqus-is-complete.html</id><summary type="html">&lt;p&gt;As stated in my previous post, I migrated all posts from &lt;a href="https://louwrentius.blogger.com"&gt;blogger.com&lt;/a&gt; to my own host running &lt;a href="http://blogofile.com"&gt;blogofile&lt;/a&gt;.
At the time of my previous post, I was not able to restore all comments made on my old blog. Thanks to some help
from &lt;a href="http://discus.com"&gt;disqcus&lt;/a&gt; I fixed an error on …&lt;/p&gt;</summary><content type="html">&lt;p&gt;As stated in my previous post, I migrated all posts from &lt;a href="https://louwrentius.blogger.com"&gt;blogger.com&lt;/a&gt; to my own host running &lt;a href="http://blogofile.com"&gt;blogofile&lt;/a&gt;.
At the time of my previous post, I was not able to restore all comments made on my old blog. Thanks to some help
from &lt;a href="http://discus.com"&gt;disqcus&lt;/a&gt; I fixed an error on my behalf and all old comments from my older blog appeared on the appropriate pages.&lt;/p&gt;
&lt;p&gt;This completes the transition from blogger to blogofile and discus (for comments). &lt;/p&gt;
&lt;p&gt;I'm now working on a controller for blogofile that recursively generates a static HTML photo blog. Relearning Python along the way.
When working properly, the code will be made available so other people can at least have a good laugh. &lt;/p&gt;
&lt;p&gt;This blog is now running on an old Intel based Mac Mini, also acting as a &lt;a href="http://code.google.com/p/lfs"&gt;firewall&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt="mini" src="/static/images/mini-server.jpg" /&gt; &lt;/p&gt;</content><category term="Uncategorized"/></entry><entry><title>Migrated this blog from blogger.com to blogofile</title><link href="https://louwrentius.com/migrated-this-blog-from-bloggercom-to-blogofile.html" rel="alternate"/><published>2010-12-30T19:21:00+01:00</published><updated>2010-12-30T19:21:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-12-30:/migrated-this-blog-from-bloggercom-to-blogofile.html</id><summary type="html">&lt;p&gt;Until now, I was hosting my blog on Google's blogger. I switched to using &lt;a href="http://www.blogofile.com" title="Blogofile"&gt;Blogofile&lt;/a&gt;. I wanted to have more control over my content and the layout. &lt;/p&gt;
&lt;p&gt;I had many issues with the blogger blog post editor, resulting in ugly posts with too much white space, strange fonts and fonts …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Until now, I was hosting my blog on Google's blogger. I switched to using &lt;a href="http://www.blogofile.com" title="Blogofile"&gt;Blogofile&lt;/a&gt;. I wanted to have more control over my content and the layout. &lt;/p&gt;
&lt;p&gt;I had many issues with the blogger blog post editor, resulting in ugly posts with too much white space, strange fonts and fonts sizes. Also, showing programming code examples with syntax highlighting is not possible with Blogger. As a nerd, I'm a control freak and I was not in control enough over my blog on blogger. &lt;/p&gt;
&lt;p&gt;So I first started thinking about hosting my own wordpress site, but soon I concluded that this is not what I want. Wordpress has similar limitations as blogger and I no longer want to be depending on some special blog software without direct access to my content. So after a tip of a friend of mine I started to look at blogofile. Blogofile generates a static HTML website, which is a real benefit if you are hosting your own site. The most important benefits are: &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Security&lt;/li&gt;
&lt;li&gt;Performance&lt;/li&gt;
&lt;li&gt;Ownership&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;p&gt;Most websites get hacked because they are basically live applications accessible from the Internet. Applications can contain bugs. If it contains security related bugs, you are toast. Software like &lt;a href="http://secunia.com/advisories/search/?search=wordpress"&gt;wordpress&lt;/a&gt; has an awful track record regarding security. Basically, if you are running a wordpress site, you must be in a state of constant fear. You also constantly have to upgrade to the latest version within a short time frame or you will be hacked. I think that wordpress is a security hazard.&lt;/p&gt;
&lt;p&gt;Blogofile generates plain text static HTML web pages. There is no dynamic content and thus no program running, except for the web server itself. There is no serious security risk.&lt;/p&gt;
&lt;h3&gt;Performance&lt;/h3&gt;
&lt;p&gt;Plain text web sites are fast. It is just data. When a visitor requests some web pages, there is no application running, laying pressure on the CPU, just plain data transfers. I bet you could host this blog without much performance problems on a recent smart phone like an Android or iOS device. &lt;/p&gt;
&lt;h3&gt;Ownership&lt;/h3&gt;
&lt;p&gt;All content is stored in a text-only format that can always easily be transformed into some other format. I use &lt;a href="http://daringfireball.net/projects/markdown/"&gt;markdown&lt;/a&gt; syntax to write new blog posts. But plain HTML can also be used. Comments can be posted through &lt;a href="http://discus.com"&gt;discus&lt;/a&gt;. It seems however that I will loose all existing comments of my original blog. New comments are showing up without a hitch, but existing imported comments do not show up. I do want to preserve them but how? I'm not sure yet. I'm thinking about incorporating them in my posts as an appendix.&lt;/p&gt;
&lt;h3&gt;The whole process of migrating to blogofile&lt;/h3&gt;
&lt;p&gt;All steps taken so far as to migrate away from blogger:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Create a wordpress installation&lt;/li&gt;
&lt;li&gt;Export blogger blog.&lt;/li&gt;
&lt;li&gt;Import blogger blog in wordpress installation&lt;/li&gt;
&lt;li&gt;'Import' the converted wordpress blog to blogofile 'format' using wordpress2blogofile.py&lt;/li&gt;
&lt;li&gt;Hack, script and fight to change all URLs so they are correct for the new site.&lt;/li&gt;
&lt;li&gt;hack, script and kill to get the old comments to show up, to no avail.&lt;/li&gt;
&lt;li&gt;Learn markdown&lt;/li&gt;
&lt;li&gt;Learn blogofile &lt;/li&gt;
&lt;li&gt;Create + steal a new website design and have to learn css and html all over again. &lt;/li&gt;
&lt;li&gt;Convert all posts from html to markdown.&lt;/li&gt;
&lt;li&gt;Fix all converted posts where necessary&lt;/li&gt;
&lt;li&gt;Put all external hosted content into a local folder and fix all links. &lt;/li&gt;
&lt;/ol&gt;</content><category term="Uncategorized"/></entry><entry><title>'Linux: using disk labels to counter storage device name changes'</title><link href="https://louwrentius.com/linux-using-disk-labels-to-counter-storage-device-name-changes.html" rel="alternate"/><published>2010-11-22T07:08:00+01:00</published><updated>2010-11-22T07:08:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-11-22:/linux-using-disk-labels-to-counter-storage-device-name-changes.html</id><summary type="html">&lt;p&gt;My router decided to change the device name for some USB storage devices.  So
/dev/sdc was swapped for /dev/sdd and vice versa. The result was some file
system corruption on /dev/sdc, because it was used on a remote system through
iSCSI, using a different file system from …&lt;/p&gt;</summary><content type="html">&lt;p&gt;My router decided to change the device name for some USB storage devices.  So
/dev/sdc was swapped for /dev/sdd and vice versa. The result was some file
system corruption on /dev/sdc, because it was used on a remote system through
iSCSI, using a different file system from /dev/sdd.&lt;/p&gt;
&lt;p&gt;With regular internal disks, attached with PATA, SATA or SAS, the chances are
very small that such an event will occur, but it is possible, especially if
you start adding/subtracting disks. With USB devices the risk is substantially
bigger.&lt;/p&gt;
&lt;p&gt;To prevent your system from mixing up drives because there device names
change, use file system labels.  All information that follows have been
&lt;a href="http://wikis.sun.com/display/BigAdmin/Using+Disk+Labels+on+Linux+File+Systems"&gt;stolen from this location&lt;/a&gt;. Since this blog is also my personal notepad,
the relevant bits are reproduced here.&lt;/p&gt;
&lt;p&gt;There are three steps involved, the third being optional:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;add a label to the file system&lt;/li&gt;
&lt;li&gt;add the label to /etc/fstab&lt;/li&gt;
&lt;li&gt;update grub boot manager (optional)&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;Add a label to the file system&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Setting a label when the file system is created:&lt;/em&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;mkfs.ext3 -L ROOT /dev/sda1
mkfs.xfs -L BIGRAID /dev/sde
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;Set label for existing file system&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;EXT3:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;e2label /dev/sda1 PRIMARY_ROOT
e2label /dev/sda1
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;XFS:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;xfs_admin -L DATA1 /dev/sdf
xfs_admin /dev/sdf
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;Set label for swap partition&lt;/em&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;mkswap -L SWAP0 /dev/sdb5
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h3&gt;add the label to fstab&lt;/h3&gt;
&lt;p&gt;Example of contents of fstab:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;LABEL=ROOT          /         ext3    defaults        1 1
LABEL=BOOT          /boot     ext3    defaults        1 2
LABEL=SWAP          swap      swap    defaults        0 0
LABEL=HOME          /home     ext3    nosuid,auto     1 2
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;h3&gt;Update the grub boot manager&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;title server
root (hd0,0)
  kernel (hd0,0)/vmlinuz ro root=LABEL=SERVER_ROOT0 rhgb quiet
  initrd (hd0,0)/initrd.img
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'Secure programming: how to implement user account management'</title><link href="https://louwrentius.com/secure-programming-how-to-implement-user-account-management.html" rel="alternate"/><published>2010-11-18T21:40:00+01:00</published><updated>2010-11-18T21:40:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-11-18:/secure-programming-how-to-implement-user-account-management.html</id><summary type="html">&lt;p&gt;Most web applications work like this:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The application uses a single database account to perform all actions. Users
are just some records in a table. Account privileges and roles are part of
this table, or separate tables.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This implies that all security must be designed and build by the application …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Most web applications work like this:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The application uses a single database account to perform all actions. Users
are just some records in a table. Account privileges and roles are part of
this table, or separate tables.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This implies that all security must be designed and build by the application
developer. I think this is entirely wrong. There is a big risk:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;In such applications, SQL-injection will allow full control of the entire
database.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This is something that is often overlooked. And the solution is simple. The
application should not use a general account with full privileges. The
application should use the database account of the user accessing the
application. All actions performed by this user are thus limited by the
privileges of this database account. The impact of SQL-injection would be
significantly reduced.&lt;/p&gt;
&lt;p&gt;The public part of a website is still using an application account, but the
privileges of this account can be significantly reduced. To obtain elevated
privileges, a user must first authenticate against the application and thus
the database.&lt;/p&gt;
&lt;p&gt;Please understand another benefit: it is not required to store
username/password combinations of privileged accounts on the application
server. The configuration file will only contain the credentials of the
unprivileged account. An attacker compromising the application server with
limited privileges, won't have access to the database with elevated
privileges.&lt;/p&gt;
&lt;p&gt;I understand that this solution requires a bit more work to setup at the
start, but once implemented, it reduces complexity and improves security so
much.&lt;/p&gt;
&lt;p&gt;Of course, the security of your data is as good as the hardening of your
database server. But that's another story.&lt;/p&gt;</content><category term="Uncategorized"/><category term="application"/><category term="security"/><category term="database"/><category term="accounts"/></entry><entry><title>The iPhone, iPad and iOS are powering a revolution</title><link href="https://louwrentius.com/the-iphone-ipad-and-ios-are-powering-a-revolution.html" rel="alternate"/><published>2010-11-06T01:12:00+01:00</published><updated>2010-11-06T01:12:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-11-06:/the-iphone-ipad-and-ios-are-powering-a-revolution.html</id><summary type="html">&lt;p&gt;Most people just don't understand computers. Are these people dumb? Some may
be dumb, but the people who make them are maybe even dumber. Because they
can't seem to figure out how to create a computer that the majority of people
understand.&lt;/p&gt;
&lt;p&gt;When the original macintosh arrived at the stage …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Most people just don't understand computers. Are these people dumb? Some may
be dumb, but the people who make them are maybe even dumber. Because they
can't seem to figure out how to create a computer that the majority of people
understand.&lt;/p&gt;
&lt;p&gt;When the original macintosh arrived at the stage back in the eighties,
computers became a bit more human-friendly, but it was limited to the
constraints of the then available hardware. It put away the text-based
interface and introduced the graphic interface. It used the desktop metaphor
to create this graphic environment. But this metaphor has had its day.&lt;/p&gt;
&lt;p&gt;Many people don't understand the desktop metaphor since they don't have a
desktop and have never used one. Also, it is a metaphor, it's to translate the
computer environment to something humans understand. But what if they don't
understand the metaphor? For example, many people just don't 'get' the Windows
Explorer or the Mac OS X finder. The desktop metaphor does not seem to fit in
how people think.&lt;/p&gt;
&lt;p&gt;Every time you see a person enter a URL like www.youtube.com in the google
search field, you will realize that we still have a long way to go.&lt;/p&gt;
&lt;p&gt;Most people did not seem to realize back then that the release of the iPhone
wasn't that important, but the release of iOS. The iPhone was the first
smartphone (a word most people are not familiar with) that did away with a
stylus or hardware keyboard. It uses what is closest to us: our fingers. A
totally new user interface, one that is very natural and close to us, is now
available.&lt;/p&gt;
&lt;p&gt;Using touch as input required a total redesign of the entire user interface.
All other interfaces were designed around hardware keyboard and mouse devices.
Fingers are big, and are obstructing the view. But it allows for a more direct
interaction with a device. And now all new smart phones sport a touch
interface.&lt;/p&gt;
&lt;p&gt;Rumors of an Apple tabled existed for long, but it was very clear when the
iPhone was released that if Apple would release a tablet, it would run this
new iOS operating system.&lt;/p&gt;
&lt;p&gt;When the iPad was released, it became an instant hit. As of today, there is no
device on the market that can be truly called a competitor. But why is this
so? The ground work has been done by the iPhone. Most people with an iPhone
will notice that aside from some performance issues in the past, the device
just always worked. It was instantly available to sent an email, look
something up on wikipedia or find the nearest Starbucks. An iPhone just always
works. No boot. Very reliable. And an interface that makes you happy.&lt;/p&gt;
&lt;p&gt;Why does iOS make people happy? Because it provides a user interface that is
human. People understand it instinctively. Any person of any age or background
will be able to use an iOS device within minutes. The interface doesn't make
you look like you are dumb because you just don't understand how it works. It
not only works, it is easy to use and you are not afraid to break anything.&lt;/p&gt;
&lt;p&gt;The iPhone and the iPad are learning a lot of people not to fear computers.&lt;/p&gt;
&lt;p&gt;The iOS does away with the old desktop metaphor, but so does Symbian or
similar interfaces. It is the combination with touch and the well thought out
interface that sets it apart from other mobile operating systems. Even when
the iOS platform did not have native applications, people still bought it and
not only because Apple released a new shiny toy.&lt;/p&gt;
&lt;p&gt;However, the app store on iOS has created a very special and important
environment. People can finally install and remove applications in an
extremely simple way. They don't need to be scared that some program will
crash your computer either while installing it, using it, or removing it. The
whole iOS ecosystem creates an environment wherein people don't need any help
any longer from other people. They are finally in control. They don't need to
be afraid of their computer.&lt;/p&gt;
&lt;p&gt;This trend will affect the old-school user interfaces such as Mac OS X. How it
will turn out is anybodies guess. But there is at least a small trend to
'eradicate' the finder as much as possible. iPhoto stores your photos. iTunes
stores your music. If you want to include a photo or song within an
application, you pick the photo or song in question from a miniature iPhoto or
iTunes interface. There is no finder anymore. The finder is disappearing from
the workflow. And why not? If programs are written well, why bother with it?
The finder should be abstracted away, as is the case on iOS, where you don't
have a finder.&lt;/p&gt;
&lt;p&gt;Another thing is multitasking, you know, that stuf we like to do, but cant. We
can only do one thing at a time. What we do want is fast task switching, not
multitasking. Sure, some programs must be running in de background, to
continue to operate, such as a chat program, but that is not the point. Most
people are just going crazy if you show how multitasking works, with different
windows. Again, iOS shows how 'multitasking' should be implemented. It is
implemented as fast application switching, allowing these applications to
register services that must continue to run, while the application itself
freezes when the user switches to another application. People tend to use one
application at a time and especially on mobile devices, every single bit of
screen real estate counts, so they are always running full screen. This full
screen notion will also be incorporated in the next Mac OS X release, Lion.
People switch, but do one thing at a time.&lt;/p&gt;
&lt;p&gt;Computer nerds tend to feel superior to people who don't have much skill using
a computer. This feeling of superiority is totally misplaced. They should be
really humble. because up until the advent of iOS, nobody was able to create a
human friendly computer interface. It is not the lack of understanding on the
side of computer users, it is the lack of  understanding on the part of the
computer nerds on how normal humans think and act.&lt;/p&gt;
&lt;p&gt;Simple, human friendly computer interfaces will liberate humanity from those
pesky computer nerds. And that will cause a bit less suffering in the world I
hope.&lt;/p&gt;</content><category term="Uncategorized"/><category term="ipad"/><category term="iphone"/><category term="user-friendly"/><category term="human"/><category term="ios"/><category term="apple"/></entry><entry><title>Apple is killing off the optical drive just like the floppy disk</title><link href="https://louwrentius.com/apple-is-killing-off-the-optical-drive-just-like-the-floppy-disk.html" rel="alternate"/><published>2010-10-23T11:05:00+02:00</published><updated>2010-10-23T11:05:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-10-23:/apple-is-killing-off-the-optical-drive-just-like-the-floppy-disk.html</id><summary type="html">&lt;p&gt;With the release of the new MacBook Air we are one step closer to killing off
the cd-rom and the dvd. As with the previous MacBook Air, this device has no
optical drive. And that is a good thing. People do not need an optical drive.
You have the network …&lt;/p&gt;</summary><content type="html">&lt;p&gt;With the release of the new MacBook Air we are one step closer to killing off
the cd-rom and the dvd. As with the previous MacBook Air, this device has no
optical drive. And that is a good thing. People do not need an optical drive.
You have the network and you have USB disks. They are faster, more reliable
and have more capacity.&lt;/p&gt;
&lt;p&gt;I may expect that in the upcoming years this trend may continue with the other
laptops. Just as Apple killed the floppy disk, it is killing the optical
drive, one step at a time. I'd rather have a smaller and lighter laptop or
more disk or battery capacity, than an optical drive. So I hope this is a
trend that will continue and all other manufacturers will follow.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'Zabbix Security: client-server communication seems insecure'</title><link href="https://louwrentius.com/zabbix-security-client-server-communication-seems-insecure.html" rel="alternate"/><published>2010-09-27T22:35:00+02:00</published><updated>2010-09-27T22:35:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-09-27:/zabbix-security-client-server-communication-seems-insecure.html</id><summary type="html">&lt;p&gt;Zabbix is a populair tool for monitoring servers, services and network
equipment. For monitoring hosts, Zabbix provides an agent that can be
installed on the hosts that must be monitored.&lt;/p&gt;
&lt;p&gt;Based on the supplied documentation and &lt;a href="http://www.zabbix.com/forum/archive/index.php/t-625.html"&gt;some remarks&lt;/a&gt; on the internets,
the 'security' of Zabbix agents seems to rely on …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Zabbix is a populair tool for monitoring servers, services and network
equipment. For monitoring hosts, Zabbix provides an agent that can be
installed on the hosts that must be monitored.&lt;/p&gt;
&lt;p&gt;Based on the supplied documentation and &lt;a href="http://www.zabbix.com/forum/archive/index.php/t-625.html"&gt;some remarks&lt;/a&gt; on the internets,
the 'security' of Zabbix agents seems to rely on an IP-filter. It only accepts
traffic from a specific IP-address. However, the protocol that is used between
the Zabbix server and agents is unencrypted and does not seem to employ any
additional authentication.&lt;/p&gt;
&lt;p&gt;With a man-in-the-middle attack, pretending to be the Zabbix server, you would
be able to compromise all servers running Zabbix. If remote commands are
enabled on these hosts, the damage that could be done may be something you
don't want to think about. Or maybe you do. Although it is true that for such
an attack to be possible, as an attacker you need access to a system within
the same network (VLAN) as the server, but none the less, it is just not
secure.&lt;/p&gt;
&lt;p&gt;Personally I don't think that Zabbix is suitable for high-security
environments, due to the lack of encryption of sensitive data and the weak
authentication mechanism.&lt;/p&gt;
&lt;p&gt;Zabbix should employ at least SSL as a means for encrypted transport and use a
password or shared secret for authentication. Even better would be the use of
client-side certificates such as implemented by the system management tool
Puppet.&lt;/p&gt;
&lt;p&gt;[update]&lt;/p&gt;
&lt;p&gt;Please note that Nagios agents also seem to work this way, but I have no
experience with Nagios so I can't say for sure.&lt;/p&gt;
&lt;p&gt;And Nagios is widely deployed in the enterprise...&lt;/p&gt;</content><category term="Uncategorized"/><category term="zabbix"/><category term="security"/></entry><entry><title>Solaris is an obsolete platform</title><link href="https://louwrentius.com/solaris-is-an-obsolete-platform.html" rel="alternate"/><published>2010-08-14T22:55:00+02:00</published><updated>2010-08-14T22:55:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-08-14:/solaris-is-an-obsolete-platform.html</id><summary type="html">&lt;p&gt;Assuming that the rumor is true and OpenSolaris will be slain by Oracle, we
must conclude that the Solaris operating system is obsolete. Solaris can be
considered legacy. Sun was a hardware shop and to sell their hardware, they
needed a great operating system.&lt;/p&gt;
&lt;p&gt;Sun had a great operating system …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Assuming that the rumor is true and OpenSolaris will be slain by Oracle, we
must conclude that the Solaris operating system is obsolete. Solaris can be
considered legacy. Sun was a hardware shop and to sell their hardware, they
needed a great operating system.&lt;/p&gt;
&lt;p&gt;Sun had a great operating system. And the Solaris platform was popular for a
long time. And I think that was for the right reasons, at that time. If you or
your company is still running on a Solaris platform, it may be time to rethink
this strategy.&lt;/p&gt;
&lt;p&gt;I do not understand why Oracle bought Sun. Oracle sells software. Sun sells
hardware. Sun had some great products, like Java, so I can see some reasons.
In the past, Solaris and Oracle had a tight relationship. But the only thing
Oracle may be doing right now is a vendor lock-in strategy, where you are
totally dependent  on both hardware and software from Oracle.&lt;/p&gt;
&lt;p&gt;But p&lt;a href="http://www.crn.com/news/channel-programs/226500112/sun-oracle-vars-differ-over-future-of-sun-hardware.htm"&gt;eople don't seem to buy this&lt;/a&gt;, literally. People do want to continue
to run Solaris, because thats the platform the've invested in. But they don't
want to pay for those exotic Solaris Sparc systems, often way more expensive
than commodity x86 hardware.&lt;/p&gt;
&lt;p&gt;Oracle invested bilions in Sun assets. How are they going to make money of it?
Squeeze out existing Sun Solaris customers who are depending on their
platform?&lt;/p&gt;
&lt;p&gt;If you are setting up a new business or if you think you can pull this off:
stay away from this legacy platform. Migrate away from Solaris. Use an open
platform that does not lock you in.&lt;/p&gt;
&lt;p&gt;And &lt;a href="http://utcc.utoronto.ca/~cks/space/blog/solaris/OracleSunFuture"&gt;this is also a very interesting&lt;/a&gt; read.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>The future of ZFS now that OpenSolaris is dead</title><link href="https://louwrentius.com/the-future-of-zfs-now-that-opensolaris-is-dead.html" rel="alternate"/><published>2010-08-14T10:51:00+02:00</published><updated>2010-08-14T10:51:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-08-14:/the-future-of-zfs-now-that-opensolaris-is-dead.html</id><summary type="html">&lt;p&gt;With the probable loss of OpenSolaris, there may be another, maybe more
devastating loss.&lt;/p&gt;
&lt;p&gt;The very popular and very advanced Zetabyte File System (ZFS)&lt;/p&gt;
&lt;p&gt;The only open source platform that actively supports ZFS is FreeBSD. And they
just 'copied' the code from OpenSolaris. Are they able to maintain and further …&lt;/p&gt;</summary><content type="html">&lt;p&gt;With the probable loss of OpenSolaris, there may be another, maybe more
devastating loss.&lt;/p&gt;
&lt;p&gt;The very popular and very advanced Zetabyte File System (ZFS)&lt;/p&gt;
&lt;p&gt;The only open source platform that actively supports ZFS is FreeBSD. And they
just 'copied' the code from OpenSolaris. Are they able to maintain and further
develop ZFS on their own? I don't think the community can handle a thing like
that. Development on ZFS will severely be hampered and will not continue in
the pace it did.&lt;/p&gt;
&lt;p&gt;It is also clear that Oracle doesn't give a shit about open source or open
operating systems. That is ok with me, everyone is entitled to their own
opinion. But keep this in mind when you decide to use any Oracle product
whatsoever.&lt;/p&gt;
&lt;p&gt;It's not that I'm suggesting that you should not buy Oracle stuff. I have no
grudge against Oracle in any way, it is just an objective observation, just be
aware of this issue.&lt;/p&gt;
&lt;p&gt;From the perspective of Oracle: what is their benefit regarding OpenSolaris? I
understand their decision, but its sad nevertheless. And I'm really scared for
the future of ZFS.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'A Moment Of Silence: OpenSolaris Is Dead'</title><link href="https://louwrentius.com/a-moment-of-silence-opensolaris-is-dead.html" rel="alternate"/><published>2010-08-04T15:39:00+02:00</published><updated>2010-08-04T15:39:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-08-04:/a-moment-of-silence-opensolaris-is-dead.html</id><summary type="html">&lt;p&gt;The last release of OpenSolaris dates back to July 2009. The next release was
scheduled for March 2010, but Oracle did not release anything. It is dead
silent around OpenSolaris.&lt;/p&gt;
&lt;p&gt;On 12 July 2010, the OpenSolaris Government Board &lt;a href="http://www.h-online.com/open/news/item/OpenSolaris-governing-board-threatens-dissolution-1037134.html"&gt;sent out an ultimatum&lt;/a&gt;
to Oracle: "please communicate with us or we …&lt;/p&gt;</summary><content type="html">&lt;p&gt;The last release of OpenSolaris dates back to July 2009. The next release was
scheduled for March 2010, but Oracle did not release anything. It is dead
silent around OpenSolaris.&lt;/p&gt;
&lt;p&gt;On 12 July 2010, the OpenSolaris Government Board &lt;a href="http://www.h-online.com/open/news/item/OpenSolaris-governing-board-threatens-dissolution-1037134.html"&gt;sent out an ultimatum&lt;/a&gt;
to Oracle: "please communicate with us or we will resign and hand over the
little power we have back to Oracle".&lt;/p&gt;
&lt;p&gt;These are all signs that OpenSolaris has no real future. And think about it:
what is Oracle's interest in OpenSolaris? Maintaining an operating system and
develop new features is extremely expensive. What is their benefit? I can't
see any. Sun was a hardware manufacturer and promoting OpenSolaris made sure
that people got experience with the operating system that powers their
hardware.&lt;/p&gt;
&lt;p&gt;Unless your environment already consists of Solaris-based systems, as of 2010,
there is no reason to use Solaris any more. OpenSolaris was, until recent, the
only operating system that supported ZFS natively, so the only choice if you
really wanted to use ZFS. Now FreeBSD has native support for ZFS too.&lt;/p&gt;
&lt;p&gt;For the people who are fanatical about ZFS this is great, because it would be
a shame if ZFS could only be used in combination with a dead operating system
that supports less hardware than Mac OS X.&lt;/p&gt;
&lt;p&gt;But I see no future in OpenSolaris and you should think twice about running
it, either as a production platform or at home. Use a platform that has a
large user-base and a big community.&lt;/p&gt;
&lt;p&gt;I think that if you are running OpenSolaris, you must start thinking about
migrating to FreeBSD or Linux, however painful that may be.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Compiling Handbrake CLI on Debian Lenny</title><link href="https://louwrentius.com/compiling-handbrake-cli-on-debian-lenny.html" rel="alternate"/><published>2010-08-03T19:31:00+02:00</published><updated>2010-08-03T19:31:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-08-03:/compiling-handbrake-cli-on-debian-lenny.html</id><summary type="html">&lt;p&gt;In this post I will show you how to compile Handbrake for Debian Lenny. Please
note that although the Handbrake GUI version does compile on Lenny, it crashes
with a segmentation fault like this:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Gtk: gtk_widget_size_allocate(): attempt to allocate widget with width -5
and height 17&lt;/p&gt;
&lt;p&gt;(ghb:1053): GStreamer-CRITICAL **: gst_element_set_state …&lt;/p&gt;&lt;/blockquote&gt;</summary><content type="html">&lt;p&gt;In this post I will show you how to compile Handbrake for Debian Lenny. Please
note that although the Handbrake GUI version does compile on Lenny, it crashes
with a segmentation fault like this:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Gtk: gtk_widget_size_allocate(): attempt to allocate widget with width -5
and height 17&lt;/p&gt;
&lt;p&gt;(ghb:1053): GStreamer-CRITICAL **: gst_element_set_state: assertion
`GST_IS_ELEMENT (element)'   failed&lt;/p&gt;
&lt;p&gt;(ghb:1053): GStreamer-CRITICAL **: gst_element_set_state: assertion
`GST_IS_ELEMENT (element)'  failed&lt;/p&gt;
&lt;p&gt;(ghb:1053): GLib-GObject-CRITICAL **: g_object_get: assertion `G_IS_OBJECT
(object)' failed&lt;/p&gt;
&lt;p&gt;Segmentation fault&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So this post only describes how to compile the command-line version of
Handbrake: HandBrakeCLI.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Issue the following apt-get commando to install all required libraries and
software:&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;apt-get install subversion yasm build-essential autoconf libtool zlib1g-dev
libbz2-dev intltool libglib2.0-dev libpthread-stubs0-dev&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Download the source code at
http://sourceforge.net/projects/handbrake/files/&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Extract the source code and cd into the new handbrake directory.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Compile handbrake like this:&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;./configure --disable-gtk --launch --force --launch-jobs=2&lt;/p&gt;
&lt;p&gt;The --launch-jobs parameter determines how many parallel threads are used for
compiling Handbrake, based on the number of CPU cores of your system. If you
have a quad-core CPU you should set this value to 4.&lt;/p&gt;
&lt;p&gt;The resulting binary is called HandBrakeCLI and can be found in the ./build
directory. Issue a 'make install' to install this binary onto your system.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Debian Lenny and Dell S300 H200 and H700 RAID controllers</title><link href="https://louwrentius.com/debian-lenny-and-dell-s300-h200-and-h700-raid-controllers.html" rel="alternate"/><published>2010-07-10T21:50:00+02:00</published><updated>2010-07-10T21:50:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-07-10:/debian-lenny-and-dell-s300-h200-and-h700-raid-controllers.html</id><summary type="html">&lt;p&gt;update november 2010: it is reported in the comments that the next release
will support these controllers. However, which controllers are supported is
not clear. Also, we may have to wait for quite some time before squeeze will
be released.&lt;/p&gt;
&lt;p&gt;Just a quick note: it seems that the new Dell …&lt;/p&gt;</summary><content type="html">&lt;p&gt;update november 2010: it is reported in the comments that the next release
will support these controllers. However, which controllers are supported is
not clear. Also, we may have to wait for quite some time before squeeze will
be released.&lt;/p&gt;
&lt;p&gt;Just a quick note: it seems that the new Dell RAID controllers are not
supported by the current stable version of Debian: Lenny. The S300, H200 and
H700 controllers as supplied with the R310, R410 and 'higher' systems, are
thus not a great choice if you want to keep things 'stock'. You may have to
run backported kernels and installer images and I couldn't figure out if these
controllers actually work with these latest images.&lt;/p&gt;
&lt;p&gt;The Perc 6/i controller is supported by Debian. It seems that it can only be
supplied with the  R410 and higher systems. If you have any additional
information, like actual experience with these controllers, please report
this.&lt;/p&gt;
&lt;p&gt;I installed VMware ESX 4.1 and installed DEbian Lenny om top of that without
problems.&lt;/p&gt;
&lt;p&gt;Please note that the network cards of the R410 are still &lt;a href="https://louwrentius.blogspot.com/2010/08/debian-lenny-and-dell-r410"&gt;not supported&lt;/a&gt;
and will cause a headache!&lt;/p&gt;
&lt;p&gt;-network-card.html&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Secure caching DNS server on Linux with DJBDNS</title><link href="https://louwrentius.com/secure-caching-dns-server-on-linux-with-djbdns.html" rel="alternate"/><published>2010-06-12T16:37:00+02:00</published><updated>2010-06-12T16:37:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-06-12:/secure-caching-dns-server-on-linux-with-djbdns.html</id><summary type="html">&lt;p&gt;The most commonly used DNS server software is ISC BIND, the "Berkeley Internet
Name Daemon". However, this software has a bad security track record and is in
my opinion a pain to configure.&lt;/p&gt;
&lt;p&gt;Mr. D.J. Bernstein developed "djbdns", which comes with a guarantee: if anyone
finds a security vulnerability …&lt;/p&gt;</summary><content type="html">&lt;p&gt;The most commonly used DNS server software is ISC BIND, the "Berkeley Internet
Name Daemon". However, this software has a bad security track record and is in
my opinion a pain to configure.&lt;/p&gt;
&lt;p&gt;Mr. D.J. Bernstein developed "djbdns", which comes with a guarantee: if anyone
finds a security vulnerability within djbdns, you will get &lt;a href="http://cr.yp.to/djbdns/guarantee.html"&gt;one thousand
dollars&lt;/a&gt;. This price has been claimed &lt;a href="http://article.gmane.org/gmane.network.djbdns/13864"&gt;once&lt;/a&gt;. But djbdns has a far
better track record than BIND.&lt;/p&gt;
&lt;p&gt;Well, attaching your own name to your DNS implementation and tying  a price to
it if someone finds a vulnerability in it, does show some confidence. But
there is more to it. D.J. Bernstein already pointed out some important
security risks regarding DNS and made djbdns immune against them, even before
it became &lt;a href="http://en.wikipedia.org/wiki/DNS_cache_poisoning"&gt;a serious world-wide security issue&lt;/a&gt;. However, djbdns is to this
day vulnerable to a variant of this type of attack and the dbndns package is
as of 2010 &lt;a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=516394"&gt;still not patched&lt;/a&gt;. Although the risk is small, you must be
aware of this. I still think that djbdns is less of a security risk,
especially regarding buffer overflows, but it is up to you to decide which
risk you want to take.&lt;/p&gt;
&lt;p&gt;The nice thing about djbdns is that it consists of several separate programs,
that each perform a dedicated task. This is in stark contrast with BIND, which
is one single program that performs all DNS functionality. One can argue that
djbdns is far more simpler and &lt;a href="http://cr.yp.to/djbdns/blurb/easeofuse.html"&gt;easy to use&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;So this post is about setting up djbdns on a Debian Linux host as a forwarding
server, thus a 'DNS cache'. This is often used to speed up DNS queries.
Clients do not have to connect to the DNS server of your ISP but can use your
local DNS server. This server will also cache the results of queries, so it
will reduce the number of DNS queries that will be sent out to your ISP DNS
server or the Internet.&lt;/p&gt;
&lt;p&gt;Debian Lenny has a patched version of djbdns in its repository. The applied
patch adds IPV6 support to djbdns. This is how you install it:&lt;/p&gt;
&lt;p&gt;apt-get install dbndns&lt;/p&gt;
&lt;p&gt;The dbndns package is actually a fork of the original djbdns software. Now the
program we need to configure is called 'dnscache', which only does one thing:
performing recursive DNS queries. This is exactly what we want.&lt;/p&gt;
&lt;p&gt;To keep things secure, the djbdns software must not be run with superuser
(root) privileges, so two accounts must be made: one for the service, and one
for logging.&lt;/p&gt;
&lt;p&gt;groupadd dnscache&lt;/p&gt;
&lt;p&gt;useradd -g dnscache dnscache&lt;/p&gt;
&lt;p&gt;useradd -g dnscache dnscachelog&lt;/p&gt;
&lt;p&gt;The next step is to configure the dnscache software like this:&lt;/p&gt;
&lt;p&gt;dnscache-conf dnscache dnscachelog /etc/dnscache 192.168.0.10&lt;/p&gt;
&lt;p&gt;The first two options tell dnscache which system user accounts to use for this
service. The /etc/dnscache directory stores the dnscache configuration. The
last option specifies which IP address to listen on. If you don't specify an
IP address, localhost (127.0.0.1) is used. If you want to run a forwarding DNS
server for your local network, you need to make dnscache listen on the IP
address on your local network, as in the example.&lt;/p&gt;
&lt;p&gt;Djbdns relies on daemontools and in order to be started by daemontools we need
to perform one last step:&lt;/p&gt;
&lt;p&gt;ln -s /etc/dnscace /etc/service/&lt;/p&gt;
&lt;p&gt;Within a couple of seconds, the dnscache software will be started by the
daemontools software. You can check it out like this:&lt;/p&gt;
&lt;p&gt;svstat /etc/service/dnscache&lt;/p&gt;
&lt;p&gt;A positive result will look like this:&lt;/p&gt;
&lt;p&gt;/etc/service/dnscache: up (pid 6560) 159 seconds&lt;/p&gt;
&lt;p&gt;However, the cache cannot be used just yet. Dnscache is governed by some text-
based configuration files in the /etc/dnscache directory. For example, the
./env/IP file contains the IP address that we configured previously on which
the service will listen.&lt;/p&gt;
&lt;p&gt;By default, only localhost will be able to access the dnscache. To allow
access to all clients on the local network you have to create a file with the
name of the network in ./root/ip/. If your network is 192.168.0.0/24 (thus 254
hosts), create a file named 192.168.0:&lt;/p&gt;
&lt;p&gt;Mini:/etc/dnscache/root/ip# pwd&lt;/p&gt;
&lt;p&gt;/etc/dnscache/root/ip&lt;/p&gt;
&lt;p&gt;Mini:/etc/dnscache/root/ip# ls&lt;/p&gt;
&lt;p&gt;192.168.0&lt;/p&gt;
&lt;p&gt;Now clients will be able to use the dnscache. Now you are running a simple
forwarding DNS server and it probably took you under ten minutes to configure
it. Although djbdns is &lt;a href="http://security-tracker.debian.org/tracker/CVE-2008-4392"&gt;not very well maintained&lt;/a&gt; in Debian Lenny, there is
currently not a really good alternative for BIND. PowerDNS is &lt;a href="http://lwn.net/Articles/368833/"&gt;not very
secure&lt;/a&gt;  (buffer overflows) and djbdns / dbndns has in more than 10 years
never been affected by this type of vulnerability.&lt;/p&gt;</content><category term="Uncategorized"/><category term="linux"/><category term="djbdns"/><category term="caching"/><category term="forwarding"/><category term="dns"/><category term="server"/><category term="bernstein"/></entry><entry><title>RAID array size and rebuild speed</title><link href="https://louwrentius.com/raid-array-size-and-rebuild-speed.html" rel="alternate"/><published>2010-04-03T23:02:00+02:00</published><updated>2010-04-03T23:02:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-04-03:/raid-array-size-and-rebuild-speed.html</id><summary type="html">&lt;p&gt;When a disk fails of a RAID 5 array, you are no longer protected against
(another) disk failure and thus data loss. During this rebuild time, you are
vulnerable. The longer it takes to rebuild your array, the longer you are
vulnerable. Especially during a disk-intensive period, because the array …&lt;/p&gt;</summary><content type="html">&lt;p&gt;When a disk fails of a RAID 5 array, you are no longer protected against
(another) disk failure and thus data loss. During this rebuild time, you are
vulnerable. The longer it takes to rebuild your array, the longer you are
vulnerable. Especially during a disk-intensive period, because the array must
be reconstructed.&lt;/p&gt;
&lt;p&gt;When one disk fails of a RAID 6 array, you are still protected against data
loss because the array can take a second disk failure. So RAID 6 is almost
always the better choice. Especially with large disks (1+ TB), because the
rebuild time largely depends on the size of a single disk, not on the size of
the entire RAID array.&lt;/p&gt;
&lt;p&gt;However, there is one catch. The size of the RAID array matters when it
becomes big, 10+ drives or more. No matter if you use hardware- or software-
based RAID, the processor must read the contents of all drives simultaneously
and use that information to rebuild the replaced drive. When creating a large
RAID array, such as in my storage array, with 20 disks, the check and rebuild
of the array becomes CPU-bound.&lt;/p&gt;
&lt;p&gt;This is because the CPU must process 1,1 GB/s (as in gigabyte!) of data and
use that data stream to rebuild that single drive. Using 1 TB drives, it
checks or rebuilds the array at about 50 MB/s, which is less than half what
the drives are capable of (100+ MB/s). Top shows that indeed the CPU is almost
saturated (95%). Please note that a check or rebuild of my storage server
takes about 5 hours currently, but that could be way shorter if the CPU was
not saturated.&lt;/p&gt;
&lt;p&gt;My array is not for professional use and fast rebuild times are not that of an
issue. But if you're more serious about your setup, it may be advised to
create more smaller RAID vollumes and glue them together using LVM or some
similar solution.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'Linux: monitor a directory for files'</title><link href="https://louwrentius.com/linux-monitor-a-directory-for-files.html" rel="alternate"/><published>2010-03-22T17:01:00+01:00</published><updated>2010-03-22T17:01:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-03-22:/linux-monitor-a-directory-for-files.html</id><summary type="html">&lt;p&gt;Inotify is a mechanism in the Linux kernel that reports when a file system
event occurs.&lt;/p&gt;
&lt;p&gt;The inotifywait comand line utility can be used in shell scripts to monitor
directories for new files. It can also be used to monitor files for changes.
Inotifywait must be installed and is often …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Inotify is a mechanism in the Linux kernel that reports when a file system
event occurs.&lt;/p&gt;
&lt;p&gt;The inotifywait comand line utility can be used in shell scripts to monitor
directories for new files. It can also be used to monitor files for changes.
Inotifywait must be installed and is often not part of the base installation
of your Linux distro. However, if you need to monitor a directory or some task
like that, it is worth the effort. (apt-get install inotify-tools).&lt;/p&gt;
&lt;p&gt;Here is how you use it:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;inotifywait -m -r -e close_write /tmp/ | while read LINE; do echo $LINE |
awk '{ print $1 $3 }'; done&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let's dissect this example one part at a time. The most interesting part is
this:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;inotifywait -m -r -e close_write /tmp/&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;What happens here? First, inotifywait monitors the /tmp directory. The
monitoring mode is specified with the -m option, otherwise inotifywait would
exit after the first event. The -r option specifies recursion, beware of large
directory trees. The -e option is the most important part. You only want to be
notified of new files if they are complete. So only after a close_write event
should your script be notified of an event. A 'create' event for example,
should not cause your script to perform any action, because the file would not
be ready yet.&lt;/p&gt;
&lt;p&gt;The remaining part of the example is just to get output like this:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;/tmp/test1234/blablaf&lt;/p&gt;
&lt;p&gt;/tmp/test123&lt;/p&gt;
&lt;p&gt;/tmp/random.bin&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This output can be used to use as an argument to other scripts or functions,
in order to perform some kind of action on this file.&lt;/p&gt;
&lt;p&gt;This mechanism is specific to Linux. So it is not a OS independent solution.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Linux"/><category term="monitor"/><category term="files"/><category term="directories"/><category term="asynchronous"/></entry><entry><title>Scanning many hosts in parallel with Nmap using PPSS</title><link href="https://louwrentius.com/scanning-many-hosts-in-parallel-with-nmap-using-ppss.html" rel="alternate"/><published>2010-02-18T21:41:00+01:00</published><updated>2010-02-18T21:41:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-02-18:/scanning-many-hosts-in-parallel-with-nmap-using-ppss.html</id><summary type="html">&lt;p&gt;Scanning a large number of hosts using Nmap often takes a lot of time. During
this time, no output is written to a file or disk. Only when Nmap is finished,
is all output written to the output file. Often, I want to start processing
results of hosts that have …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Scanning a large number of hosts using Nmap often takes a lot of time. During
this time, no output is written to a file or disk. Only when Nmap is finished,
is all output written to the output file. Often, I want to start processing
results of hosts that have already been scanned. Often, the trick is to split
the input file with all the hosts and start multiple Nmap instances by hand
using the different input files. This is rather cumbersome. Now what I really
want is that I get the results of a scan of a particular host immediately
available as soon as it's finished. Here is where PPSS comes in. PPSS can
start Nmap scans and proces a list of hosts as contained in an input file.
PPSS will only start a predefined max number of simultaneous scans in
parallel, as not to overwhelm the scanner, network or target hosts. This is an
example on how PPSS can be used to obtain results immediately:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;./ppss -f hosts.txt -c 'nmap -n -v -sS -A -p- -oN "$ITEM" "$ITEM"' -p 4&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Where hosts.txt contains IP-addresses, networks or domain names like:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;192.168.0.1&lt;/p&gt;
&lt;p&gt;192.168.0.2&lt;/p&gt;
&lt;p&gt;192.168.0.3&lt;/p&gt;
&lt;p&gt;192.168.1.1-254&lt;/p&gt;
&lt;p&gt;www.google.nl&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The 'ITEM' part is the fun bit. In this example, multiple instances of Nmap
will scan a single hosts. The output is written to a file called "$ITEM",
which is of course substituted for the IP-address or domain name as read from
hosts.txt. The second "$ITEM" is the argument to Nmap which tells which host
to scan. The -p 4 option tells PPSS to run 4 nmap scans simultaneously at all
times.&lt;/p&gt;
&lt;p&gt;You will end up with a large number of output files, one per host. As soon as
a scan is finished on one host, you can start processing the results, instead
of waiting for that big scan to finish.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Corsair CM PSU-750HX seems ok</title><link href="https://louwrentius.com/corsair-cm-psu-750hx-seems-ok.html" rel="alternate"/><published>2010-02-10T23:59:00+01:00</published><updated>2010-02-10T23:59:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-02-10:/corsair-cm-psu-750hx-seems-ok.html</id><summary type="html">&lt;p&gt;I had to replace my Coolermaster PSU and after some searching on the interweb,
I chose the Corsair CMPSU-750HX. One of the reasons is that Corsair states
that this PSU can withstand 50 degree Celcius in continuous operation on full
load.&lt;/p&gt;
&lt;p&gt;The package is very, clean, with all the cables …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I had to replace my Coolermaster PSU and after some searching on the interweb,
I chose the Corsair CMPSU-750HX. One of the reasons is that Corsair states
that this PSU can withstand 50 degree Celcius in continuous operation on full
load.&lt;/p&gt;
&lt;p&gt;The package is very, clean, with all the cables in some neat pouch and the PSU
itself also in a neat bag. You pay quite some money, but it at least suggest
quality. The modular design with the modular kables is excellent.&lt;/p&gt;
&lt;p&gt;Personally, I think that PSUs with multiple 12v rails are not that usefull.
This particular PSU has just one single 12v rail that can be loaded up to full
capacity of the PSU. I think this makes the design easier and if you are
running heavy systems that have short spikes (starting al drives) this is
ideal.&lt;/p&gt;
&lt;p&gt;I hope this one lasts longer.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Smoking coolermaster Silent Pro M 600W TN6M50</title><link href="https://louwrentius.com/smoking-coolermaster-silent-pro-m-600w-tn6m50.html" rel="alternate"/><published>2010-02-10T00:46:00+01:00</published><updated>2010-02-10T00:46:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-02-10:/smoking-coolermaster-silent-pro-m-600w-tn6m50.html</id><summary type="html">&lt;p&gt;So I was just messing around on my work station, when suddenly I smelled the
smell any person familiar with electronics fears. The smell of some electrical
component burning.&lt;/p&gt;
&lt;p&gt;The whole upper floor smelled like something was smoldering. So I shut down
both my storage servers. After half an hour …&lt;/p&gt;</summary><content type="html">&lt;p&gt;So I was just messing around on my work station, when suddenly I smelled the
smell any person familiar with electronics fears. The smell of some electrical
component burning.&lt;/p&gt;
&lt;p&gt;The whole upper floor smelled like something was smoldering. So I shut down
both my storage servers. After half an hour I still hadn't found the source of
the smell, but it definitely was my 18 TB NAS.&lt;/p&gt;
&lt;p&gt;So I switched it back on to see if I could determine the cause. The smell
became stronger and within the strike light of my flash light, I saw small
strands of grey smoke slowly twirling out of the Coolermaster Silent Pro M
600W power supply.&lt;/p&gt;
&lt;p&gt;That was the moment I decided to turn the system off immediately. I know this
kind of thing can happen. But it is still very bad for such a component to
crap out on me like that.&lt;/p&gt;
&lt;p&gt;Needless to say that I don't want a replacement of this model in my server. I
will now try my luck with the Corsair CMPSU-750HX 750Watt PSU.&lt;/p&gt;
&lt;p&gt;Based on a single experience it cannot be concluded that this Coolermaster PSU
is a bad one that should be avoided. But the only moving part of a PSU is the
(big) fan. What must be wrong with it that it decided to start smoking?&lt;/p&gt;
&lt;p&gt;For reasons of availability, a redundant power supply should be used, but that
is just too expensive for my taste ($500+).&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Is the iPhone OS a threat to our freedom?</title><link href="https://louwrentius.com/is-the-iphone-os-a-threat-to-our-freedom.html" rel="alternate"/><published>2010-01-31T19:55:00+01:00</published><updated>2010-01-31T19:55:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-01-31:/is-the-iphone-os-a-threat-to-our-freedom.html</id><summary type="html">&lt;p&gt;There is one fundamental flaw with both the iPhone and the iPad. As a user,
you do not have full control over your device. You can only install or run
software that is approved by Apple.&lt;/p&gt;
&lt;p&gt;This is something that is unprecedented. All major platforms, Windows, Linux,
Mac OS X …&lt;/p&gt;</summary><content type="html">&lt;p&gt;There is one fundamental flaw with both the iPhone and the iPad. As a user,
you do not have full control over your device. You can only install or run
software that is approved by Apple.&lt;/p&gt;
&lt;p&gt;This is something that is unprecedented. All major platforms, Windows, Linux,
Mac OS X do provide the user with full control over what programs can be run
or not.&lt;/p&gt;
&lt;p&gt;Is this a bad thing? Are you trading your freedom for some luxurious gadget
such as the iPhone or the iPad?&lt;/p&gt;
&lt;p&gt;I say no. People are over reacting.&lt;/p&gt;
&lt;p&gt;You would trade in your freedom and become 'owned' by Apple, if an iPhone or
iPad is your sole computing device.&lt;/p&gt;
&lt;p&gt;However, everybody also has a computer at home, that is still under your full
control.Since the iPhone and iPad is just an auxiliary device (although quite
powerful), you are still free.&lt;/p&gt;
&lt;p&gt;Most importantly, I think it is about the content, not the device. Do you
retain control over your own content, such as music, files and e-mail? I think
so. I think that on this level, which is most crucial, Apple does not restrict
people on iPhones or iPads in any way. And that is what matters most I think.&lt;/p&gt;</content><category term="Uncategorized"/><category term="iphone"/><category term="ipad"/><category term="freedom"/></entry><entry><title>Why the iPad will be a breakthrough in human computing</title><link href="https://louwrentius.com/why-the-ipad-will-be-a-breakthrough-in-human-computing.html" rel="alternate"/><published>2010-01-30T10:50:00+01:00</published><updated>2010-01-30T10:50:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-01-30:/why-the-ipad-will-be-a-breakthrough-in-human-computing.html</id><summary type="html">&lt;p&gt;The fact is that computers aren't made for humans. Computers are just made,
and humans have to adjust to them.&lt;/p&gt;
&lt;p&gt;The problem is that most people that are not into technology just don't
understand how computers work. Should I single click of double click? Click
left or right?&lt;/p&gt;
&lt;p&gt;The only …&lt;/p&gt;</summary><content type="html">&lt;p&gt;The fact is that computers aren't made for humans. Computers are just made,
and humans have to adjust to them.&lt;/p&gt;
&lt;p&gt;The problem is that most people that are not into technology just don't
understand how computers work. Should I single click of double click? Click
left or right?&lt;/p&gt;
&lt;p&gt;The only people that can work with some ease on computers are people with a
more than average interest in technology. Ordinary people often have to fight
great battles to get the job done. The therm 'ordinary' does not justice to
these people, because technologists seem to forget that &lt;a href="http://speirs.org/blog/2010/1/29/future-shock.html"&gt;they are the people
that actually do something useful.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The iPad is the first personal computer that is actually made for humans that
do not have a primary interest in computers. The entire computer is abstracted
away to focus on the things you really want to do. People do not need the help
of technologists anymore to do the things they want.&lt;/p&gt;
&lt;p&gt;The iPhone was the first in this new kind of computers, but due to it's size
it's still a bit of a gimmick. But it was a revolution within the world of
smart phones. It was the first device that was actually usable for non-
technologists. And the iPad will be the first 'regular' computer that
(hopefully) won't be such a nuisance as current home computers are.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>The iPad will be the death of Flash</title><link href="https://louwrentius.com/the-ipad-will-be-the-death-of-flash.html" rel="alternate"/><published>2010-01-30T10:16:00+01:00</published><updated>2010-01-30T10:16:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-01-30:/the-ipad-will-be-the-death-of-flash.html</id><summary type="html">&lt;p&gt;So Apple finally released their tablet computer: the iPad. One of the most
debated drawbacks is that it lacks support for Adobe Flash. The iPhone does
not support Flash either, and since the iPad is based on the iPhone OS, this
should not come as a surprise.&lt;/p&gt;
&lt;p&gt;Now many people …&lt;/p&gt;</summary><content type="html">&lt;p&gt;So Apple finally released their tablet computer: the iPad. One of the most
debated drawbacks is that it lacks support for Adobe Flash. The iPhone does
not support Flash either, and since the iPad is based on the iPhone OS, this
should not come as a surprise.&lt;/p&gt;
&lt;p&gt;Now many people see this as a serious problem. &lt;a href="http://www.kungfugrippe.com/post/360209059/the-flash-blog-the-ipad-"&gt;There are a slew of websites
that cannot be viewed on an iPad for this reason&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;However, the thing is this: Flash sucks. It is a proprietary technology under
the control of Adobe and the only reason it is currently popular is that it
provides a kind of standard for video playback across all browsers and
operating systems. But it still sucks. It crashes. It is shit.&lt;/p&gt;
&lt;p&gt;The iPhone is immensely popular, despite the lack of flash. The iPhone user
base is huge. By using Flash in your website, you are excluding a large
population of potential visitors. So this is what will happen: websites will
start dumping Flash. The iPhone and the iPad will together kill Flash.&lt;/p&gt;
&lt;p&gt;And that is a good thing for everybody, especially for proponents of open
standards and open formats. Oh irony, that it will take a closed proprietary
platform to do so.&lt;/p&gt;
&lt;p&gt;provides-the-ultimate&lt;/p&gt;</content><category term="Uncategorized"/><category term="ipad"/><category term="iphone"/><category term="kill"/><category term="flash"/></entry><entry><title>Mounting a file system or partition from a disk image</title><link href="https://louwrentius.com/mounting-a-file-system-or-partition-from-a-disk-image.html" rel="alternate"/><published>2010-01-23T10:13:00+01:00</published><updated>2010-01-23T10:13:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-01-23:/mounting-a-file-system-or-partition-from-a-disk-image.html</id><summary type="html">&lt;p&gt;You cannot just make a disk copy with dd and then just mount it as a regular
disk. You must know where the partition starts on the disk. So first, you need
to get the partition table with sfdisk:&lt;/p&gt;
&lt;p&gt;sfdisk -l -uS image_file.dd&lt;/p&gt;
&lt;p&gt;The output is something like:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;Disk …&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</summary><content type="html">&lt;p&gt;You cannot just make a disk copy with dd and then just mount it as a regular
disk. You must know where the partition starts on the disk. So first, you need
to get the partition table with sfdisk:&lt;/p&gt;
&lt;p&gt;sfdisk -l -uS image_file.dd&lt;/p&gt;
&lt;p&gt;The output is something like:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;Disk /mnt/image/image_file.dd: 9729 cylinders, 255 heads, 63 sectors/track
Warning: The partition table looks like it was made
for C/H/S=*/240/63 (instead of 9729/255/63).

For this listing I&amp;#39;ll assume that geometry.

Units = sectors of 512 bytes, counting from 0

Device Boot Start End #sectors Id System

/mnt/image/simon-besmet.img1 63 8497439 8497377 b W95 FAT32
/mnt/image/simon-besmet.img2 * 8497440 156280319 147782880 7 HPFS/NTFS
/mnt/image/simon-besmet.img3 0 - 0 0 Empty
/mnt/image/simon-besmet.img4 0 - 0 0 Empty
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Next, we need to calculate the actual starting point of the partition. The
sector number is in sectors, which contain 512 bytes. So in this case, the
starting point of the NTFS partition is 8497440 x 512 = 4350689280.&lt;/p&gt;
&lt;p&gt;To mount the image, enter the following command, using the calculated offset:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;mount -o loop,offset=4350689280 /mnt/image/disk_image.dd /mnt/disk
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Source:&lt;/p&gt;
&lt;p&gt;http://lists.samba.org/archive/linux/2005-April/013444.html&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'Linux: show graphical layout of disk temperatures'</title><link href="https://louwrentius.com/linux-show-graphical-layout-of-disk-temperatures.html" rel="alternate"/><published>2010-01-03T03:12:00+01:00</published><updated>2010-01-03T03:12:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2010-01-03:/linux-show-graphical-layout-of-disk-temperatures.html</id><summary type="html">&lt;p&gt;graphic, representation&lt;/p&gt;
&lt;p&gt;To get a visual representation of hard drive temperatures, I wrote a small
script. The output of this script looks like this:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://members.multiweb.nl/nan1/img/drivetempcolour.jpg"&gt;&lt;img alt="image" src="http://members.multiweb.nl/nan1/img/drivetempcolour.jpg" /&gt;&lt;/a&gt;This output is tailored to the exact disk lay-out of my storage
server. However, it is also usable for other servers. You have to edit the …&lt;/p&gt;</summary><content type="html">&lt;p&gt;graphic, representation&lt;/p&gt;
&lt;p&gt;To get a visual representation of hard drive temperatures, I wrote a small
script. The output of this script looks like this:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://members.multiweb.nl/nan1/img/drivetempcolour.jpg"&gt;&lt;img alt="image" src="http://members.multiweb.nl/nan1/img/drivetempcolour.jpg" /&gt;&lt;/a&gt;This output is tailored to the exact disk lay-out of my storage
server. However, it is also usable for other servers. You have to edit the
lay-out depending on the system.&lt;/p&gt;
&lt;p&gt;This script assumes that you have smartmontools installed on your system. It
uses smartctl to obtain the drive temperatures.&lt;/p&gt;
&lt;p&gt;The script can be found &lt;a href="http://members.multiweb.nl/nan1/got/show-hdd-temp.sh"&gt;here&lt;/a&gt; or &lt;a href="http://members.multiweb.nl/nan1/got/show-hdd-temp.tgz"&gt;here in tgz format&lt;/a&gt;.&lt;/p&gt;</content><category term="Uncategorized"/><category term="linux"/><category term="hard"/><category term="disk"/><category term="drive"/><category term="temperature"/><category term="smartmontools"/><category term="script"/><category term="colour"/><category term="layout"/></entry><entry><title>Recovering a lost partition using gpart</title><link href="https://louwrentius.com/recovering-a-lost-partition-using-gpart.html" rel="alternate"/><published>2009-12-22T19:12:00+01:00</published><updated>2009-12-22T19:12:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-12-22:/recovering-a-lost-partition-using-gpart.html</id><summary type="html">&lt;p&gt;Even today people do not understand how important it is for the safety of your
data to make backups. I was asked to perform some data recovery on a hard
drive of an old computer, which still contained important documents and
photo's.&lt;/p&gt;
&lt;p&gt;The first thing I did was to make …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Even today people do not understand how important it is for the safety of your
data to make backups. I was asked to perform some data recovery on a hard
drive of an old computer, which still contained important documents and
photo's.&lt;/p&gt;
&lt;p&gt;The first thing I did was to make a disk image with ddrescue. I always work
with the image and not with the original drive, to prevent any risk of
accidentally messing things up for good.&lt;/p&gt;
&lt;p&gt;Example:&lt;/p&gt;
&lt;p&gt;ddrescue -r 2 -v if=/dev/sdf of=/storage/image/diskofperson.dd bs=1M&lt;/p&gt;
&lt;p&gt;Next, I tried using gparted on this file but got this error:&lt;/p&gt;
&lt;p&gt;Welcome to GNU Parted! Type 'help' to view a list of commands.&lt;/p&gt;
&lt;p&gt;(parted) p&lt;/p&gt;
&lt;p&gt;Error: /storage/image/diskofperson.dd: unrecognised disk label&lt;/p&gt;
&lt;p&gt;(parted) quit&lt;/p&gt;
&lt;p&gt;Also fdisk -l didn't work:&lt;/p&gt;
&lt;p&gt;Disk /storage/image/diskofperson.dd doesn't contain a valid partition table&lt;/p&gt;
&lt;p&gt;It seemed that the partition table was gone. I used the utility testdisk to
recover this partition, to no avail. Why this tool didn't work is beyond me.&lt;/p&gt;
&lt;p&gt;I found a very old utility called 'gpart' that just searches a disk for
existing partitions. I just want to know the starting offset of the relevant
partition.&lt;/p&gt;
&lt;p&gt;So I ran:&lt;/p&gt;
&lt;p&gt;gpart -g /storage/image/diskofperson.dd&lt;/p&gt;
&lt;p&gt;And I got nothing useful, although a partition was found:&lt;/p&gt;
&lt;p&gt;Begin scan...&lt;/p&gt;
&lt;p&gt;Possible partition(DOS FAT), size(57255mb), offset(0mb)&lt;/p&gt;
&lt;p&gt;End scan.&lt;/p&gt;
&lt;p&gt;So I ran the command again with more verbosity:&lt;/p&gt;
&lt;p&gt;gpart -g /storage/image/diskofperson.dd&lt;/p&gt;
&lt;p&gt;...&lt;/p&gt;
&lt;p&gt;Begin scan...&lt;/p&gt;
&lt;p&gt;Possible partition(DOS FAT), size(57255mb), offset(0mb)&lt;/p&gt;
&lt;p&gt;type: 011(0x0B)(DOS or Windows 95 with 32 bit FAT)&lt;/p&gt;
&lt;p&gt;size: 57255mb #s(117258372) s(63-117258434)&lt;/p&gt;
&lt;p&gt;chs: (1023/255/0)-(1023/255/0)d (0/0/0)-(0/0/0)r&lt;/p&gt;
&lt;p&gt;hex: 00 FF C0 FF 0B FF C0 FF 3F 00 00 00 84 38 FD 06&lt;/p&gt;
&lt;p&gt;End scan.&lt;/p&gt;
&lt;p&gt;...&lt;/p&gt;
&lt;p&gt;This time I got something useful. The s(63-117258434) part shows the starting
sector, which is 63. A sector is 512 bytes, so the exact starting offset of
the partition is 32256.&lt;/p&gt;
&lt;p&gt;So to mount this partition, just issue:&lt;/p&gt;
&lt;p&gt;mount -o loop,ro,offset=32256 /storage/image/diskofperson.dd /mnt/recovery&lt;/p&gt;
&lt;p&gt;And voilá, access to the filesystem has been obtained.&lt;/p&gt;
&lt;p&gt;/storage/image/jdiskofperson.dd on /mnt/recovery type vfat
(ro,loop=/dev/loop0,offset=32256)&lt;/p&gt;</content><category term="Uncategorized"/><category term="data"/><category term="recovery"/><category term="gpart"/><category term="linux"/><category term="partition"/><category term="search"/></entry><entry><title>Wake On Lan not working with realtek r8168 card</title><link href="https://louwrentius.com/wake-on-lan-not-working-with-realtek-r8168-card.html" rel="alternate"/><published>2009-12-20T15:18:00+01:00</published><updated>2009-12-20T15:18:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-12-20:/wake-on-lan-not-working-with-realtek-r8168-card.html</id><summary type="html">&lt;p&gt;After messing around with different kernels on Debian Lenny, I noticed that my
system did no longer respond to WOL packets. The system is using an on-board
Realtek R8168 chip which supports wake on lan.&lt;/p&gt;
&lt;p&gt;After searching and reading i found the problem. The system is using an r8168
chip …&lt;/p&gt;</summary><content type="html">&lt;p&gt;After messing around with different kernels on Debian Lenny, I noticed that my
system did no longer respond to WOL packets. The system is using an on-board
Realtek R8168 chip which supports wake on lan.&lt;/p&gt;
&lt;p&gt;After searching and reading i found the problem. The system is using an r8168
chip, but the driver that is loaded by Linux is the r8169 driver. If the r8168
driver is loaded, as it should be, then WOL is working again.&lt;/p&gt;
&lt;p&gt;See also &lt;a href="https://bugs.launchpad.net/linux/+bug/160413"&gt;this information&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The trick is to blacklist the r8169 module. To do so, edit the
/etc/moprobe.d/blacklist file and add a line reading 'blacklist r8169'&lt;/p&gt;
&lt;p&gt;To make this permanent, issue the following commands as root or with sudo:&lt;/p&gt;
&lt;p&gt;depmod -a&lt;/p&gt;
&lt;p&gt;mkinitramfs -o /boot/initrd.img-$(uname -r) $(uname -r)&lt;/p&gt;
&lt;p&gt;After a reboot, wake on lan should be working again.&lt;/p&gt;</content><category term="Uncategorized"/><category term="debian"/><category term="wake"/><category term="on"/><category term="lan"/><category term="wol"/><category term="realtek"/><category term="r8168"/><category term="r8169"/></entry><entry><title>Shunit2, unit testing for shell scripts</title><link href="https://louwrentius.com/shunit2-unit-testing-for-shell-scripts.html" rel="alternate"/><published>2009-12-17T16:47:00+01:00</published><updated>2009-12-17T16:47:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-12-17:/shunit2-unit-testing-for-shell-scripts.html</id><summary type="html">&lt;p&gt;This may be of interest to people who are as stupid as I am and write
elaborate shell scripts instead of using a proper scripting language such as
Python or Ruby. No I am deliberately not mentioning Perl here.&lt;/p&gt;
&lt;p&gt;Anyway, testing is always an issue. With PPSS, I encountered many …&lt;/p&gt;</summary><content type="html">&lt;p&gt;This may be of interest to people who are as stupid as I am and write
elaborate shell scripts instead of using a proper scripting language such as
Python or Ruby. No I am deliberately not mentioning Perl here.&lt;/p&gt;
&lt;p&gt;Anyway, testing is always an issue. With PPSS, I encountered many times that
some change broke something in another place. Testing if some change screwed
things up manually is just tedious and a pain.&lt;/p&gt;
&lt;p&gt;As any person who is semi-serious about programming should have done already,
I started to write some unit tests. For bash scripts, there is this unit test
framework called &lt;a href="http://code.google.com/p/shunit2/"&gt;Sunit2&lt;/a&gt;. It takes some effort to write tests. But once
you have written some tests and witness how the tests that passed before now
fail after you changed some code is priceless. Because often, you would not
have found the issue before a long time.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Google DNS - what to think of it?</title><link href="https://louwrentius.com/google-dns-what-to-think-of-it.html" rel="alternate"/><published>2009-12-03T18:42:00+01:00</published><updated>2009-12-03T18:42:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-12-03:/google-dns-what-to-think-of-it.html</id><summary type="html">&lt;p&gt;Google now provide an open DNS service. At first I was scared that they use
their service to get information about users.&lt;/p&gt;
&lt;p&gt;However, their &lt;a href="http://code.google.com/intl/nl-NL/speed/public-dns/privacy.html"&gt;privacy statement&lt;/a&gt; tells us that no personal identifiable
information is stored for longer than 48 hours. The permanent logs do not
contain such information. The most …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Google now provide an open DNS service. At first I was scared that they use
their service to get information about users.&lt;/p&gt;
&lt;p&gt;However, their &lt;a href="http://code.google.com/intl/nl-NL/speed/public-dns/privacy.html"&gt;privacy statement&lt;/a&gt; tells us that no personal identifiable
information is stored for longer than 48 hours. The permanent logs do not
contain such information. The most notable information that is stored
permanently is the requested domain. The other thing is that they record the
location of the request on the city level. And even that info is only stored
for two weeks. After that, only a small random sample of info is stored for
permanent storage.&lt;/p&gt;
&lt;p&gt;The main question is now: who do you trust more: Google or your ISP.&lt;/p&gt;
&lt;p&gt;To be honest, I think I trust Google more than my ISP. I don't think my ISP
adheres to the same privacy policy.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Convert dos file to linux format wit vim</title><link href="https://louwrentius.com/convert-dos-file-to-linux-format-wit-vim.html" rel="alternate"/><published>2009-12-03T17:12:00+01:00</published><updated>2009-12-03T17:12:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-12-03:/convert-dos-file-to-linux-format-wit-vim.html</id><summary type="html">&lt;p&gt;If you have some file that has been saved on a (Win)do(w)s host you may notice
that all lines end with ^M.&lt;/p&gt;
&lt;p&gt;To fix this, you can use the tool dos2unix. If however this tool is not at
your disposal, you may have a problem. If vim …&lt;/p&gt;</summary><content type="html">&lt;p&gt;If you have some file that has been saved on a (Win)do(w)s host you may notice
that all lines end with ^M.&lt;/p&gt;
&lt;p&gt;To fix this, you can use the tool dos2unix. If however this tool is not at
your disposal, you may have a problem. If vim is available, you do not have a
problem:&lt;/p&gt;
&lt;p&gt;The trick is to delete all occurances of ^M with this line:&lt;/p&gt;
&lt;p&gt;:%s/ctrl-v ctrl-m//g&lt;/p&gt;
&lt;p&gt;This will look like:&lt;/p&gt;
&lt;p&gt;:%s/^M//g&lt;/p&gt;
&lt;p&gt;Just save the file and you're done.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Which file system for a large storage array under Linux?</title><link href="https://louwrentius.com/which-file-system-for-a-large-storage-array-under-linux.html" rel="alternate"/><published>2009-11-30T13:03:00+01:00</published><updated>2009-11-30T13:03:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-30:/which-file-system-for-a-large-storage-array-under-linux.html</id><summary type="html">&lt;p&gt;There are many file systems available under Linux, however only a few of them
can be used for a large storage array.&lt;/p&gt;
&lt;p&gt;I am assuming that you want to create a single file system. I don't care if
you use LVM or other layers beneath, this is about which file …&lt;/p&gt;</summary><content type="html">&lt;p&gt;There are many file systems available under Linux, however only a few of them
can be used for a large storage array.&lt;/p&gt;
&lt;p&gt;I am assuming that you want to create a single file system. I don't care if
you use LVM or other layers beneath, this is about which file system to use.&lt;/p&gt;
&lt;p&gt;I will discuss each file system in short.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;EXT3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Old and trusted. but slow, wastes tremendous amounts of free space and has an
16 TB limit. Not recommended. At 16 TB, you will lose significant amounts of
free space.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;JFS&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Developed by IBM, it seems an ok file system and it supports 16+ TB file
systems. However it is abandoned by IBM and does not seem to have a future.
The reason I did not choose JFS is because it does not seem to be in wide
spread use and therefore, and I do not want to take any risk in this regard. I
might encounter some rare bug because I would be one of the few Linux jfs
users that creates 16+ TB file systems.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;XFS&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A file systems that works. Supports 16+ TB file systems and is widely used. It
has some drawbacks, such as data loss (files are zeroed) when something goes
wrong (powerloss) however, nobody that is interested in creating a large
filesystem is going to run the box without a UPS.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Reiserfs&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The guy who designed and wrote it is in jail for killing his wife. Not much
future here, i suppose. Also, it does not support file systems bigger than 16
TB.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Reiser4&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Some new version of Reiserfs which is still not available as part of a stable
Linux kernel.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;EXT4&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Ext3 upgraded to current days need, although with a draw back. On paper, it
supports 16 TB+&lt;/p&gt;
&lt;p&gt;file system, but currently, in practice, it does not. I found out the hard way
and had to reformat my array with another file system.&lt;/p&gt;
&lt;p&gt;My choice:&lt;/p&gt;
&lt;p&gt;Honestly, there is not much of an option currently under Linux other than XFS.
In the past, I had some quirks with file names that contained strange
characters causing trouble. However, I never lost any data whatsoever.&lt;/p&gt;
&lt;p&gt;Currently, what I'm really hoping for is ZFS for Linux or a stable version of
btrfs. These are truly modern day file systems with support for snapshots,
etc. But this is still a dream. Until then, I will stick with XFS.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'Tip of the day: Scrolling in GNU screen'</title><link href="https://louwrentius.com/tip-of-the-day-scrolling-in-gnu-screen.html" rel="alternate"/><published>2009-11-30T11:44:00+01:00</published><updated>2009-11-30T11:44:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-30:/tip-of-the-day-scrolling-in-gnu-screen.html</id><summary type="html">&lt;p&gt;Just the answer:&lt;/p&gt;
&lt;p&gt;By default, on Debian, the scroll back buffer is about 1K lines. This can be
changed in the .screenrc file in your home directory. The following example
sets the scroll back buffer to 5K lines.&lt;/p&gt;
&lt;p&gt;defscrollback 5000&lt;/p&gt;
&lt;p&gt;Set the scroll back buffer on the fly with:&lt;/p&gt;
&lt;p&gt;First …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Just the answer:&lt;/p&gt;
&lt;p&gt;By default, on Debian, the scroll back buffer is about 1K lines. This can be
changed in the .screenrc file in your home directory. The following example
sets the scroll back buffer to 5K lines.&lt;/p&gt;
&lt;p&gt;defscrollback 5000&lt;/p&gt;
&lt;p&gt;Set the scroll back buffer on the fly with:&lt;/p&gt;
&lt;p&gt;First enter the command line mode:&lt;/p&gt;
&lt;p&gt;ctrl + a, :&lt;/p&gt;
&lt;p&gt;Then enter:&lt;/p&gt;
&lt;p&gt;scrollback 2000&lt;/p&gt;
&lt;p&gt;To set the scroll back buffer to 2000 lines.&lt;/p&gt;
&lt;p&gt;To actually scroll back, the actuall stuff why you may be reading this post:&lt;/p&gt;
&lt;p&gt;First enter copy mode:&lt;/p&gt;
&lt;p&gt;ctrl + a, [&lt;/p&gt;
&lt;p&gt;Use standard VI controls to navigate through the lines (h j k l).&lt;/p&gt;
&lt;p&gt;Use ctrl+b to scroll a full page up&lt;/p&gt;
&lt;p&gt;Use ctrl+f to scroll a full page down.&lt;/p&gt;
&lt;p&gt;For more details, please visit&lt;a href="http://www.samsarin.com/blog/2007/03/11/gnu-screen-working-with-the-"&gt; this link&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;scrollback-buffer/&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'Gzip with parallel compression support: pigz'</title><link href="https://louwrentius.com/gzip-with-parallel-compression-support-pigz.html" rel="alternate"/><published>2009-11-22T18:29:00+01:00</published><updated>2009-11-22T18:29:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-22:/gzip-with-parallel-compression-support-pigz.html</id><summary type="html">&lt;p&gt;The speed at which files are compressed with gzip is currently almost always
determined by the speed of the CPU. However, standard unix gzip is single-
threaded and only uses a single CPU (core).&lt;/p&gt;
&lt;p&gt;However, the maintainer of the zlib library has released&lt;a href="http://www.zlib.net/pigz/"&gt; 'pigz' or 'pig-zee'
&lt;/a&gt;whichs adds just that …&lt;/p&gt;</summary><content type="html">&lt;p&gt;The speed at which files are compressed with gzip is currently almost always
determined by the speed of the CPU. However, standard unix gzip is single-
threaded and only uses a single CPU (core).&lt;/p&gt;
&lt;p&gt;However, the maintainer of the zlib library has released&lt;a href="http://www.zlib.net/pigz/"&gt; 'pigz' or 'pig-zee'
&lt;/a&gt;whichs adds just that: support for parallel compression. This dramatically
improves the speed at which a file can be gzipped.&lt;/p&gt;
&lt;p&gt;In this example, a 3 GB compressable file is gzipped:&lt;/p&gt;
&lt;p&gt;Gzip:&lt;/p&gt;
&lt;p&gt;root@Core7i:~# time gzip pigz.bin&lt;/p&gt;
&lt;p&gt;real 1m58.994s&lt;/p&gt;
&lt;p&gt;user 1m56.480s&lt;/p&gt;
&lt;p&gt;sys 0m1.820s&lt;/p&gt;
&lt;p&gt;Pigz:&lt;/p&gt;
&lt;p&gt;root@Core7i:~# time pigz pigz.bin&lt;/p&gt;
&lt;p&gt;real 0m31.524s&lt;/p&gt;
&lt;p&gt;user 2m54.890s&lt;/p&gt;
&lt;p&gt;sys 0m2.900s&lt;/p&gt;
&lt;p&gt;This simple and a bit unscientific example shows a 400% speed improvement.
Since the Core i7 has four real cores, this shows that pigz scales nicely.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>How to determine which process causes IO ?</title><link href="https://louwrentius.com/how-to-determine-which-process-causes-io.html" rel="alternate"/><published>2009-11-22T15:19:00+01:00</published><updated>2009-11-22T15:19:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-22:/how-to-determine-which-process-causes-io.html</id><summary type="html">&lt;p&gt;There is a nifty little program called 'iotop'. Iotop is part of Debian or
Ubuntu and can be installed with a simple apt-get.&lt;/p&gt;
&lt;p&gt;Once you have determined with 'top' that the system is waiting on IO-access,
It is nice to know&lt;/p&gt;
&lt;p&gt;which process is responsibe for this IO. Therefore, you …&lt;/p&gt;</summary><content type="html">&lt;p&gt;There is a nifty little program called 'iotop'. Iotop is part of Debian or
Ubuntu and can be installed with a simple apt-get.&lt;/p&gt;
&lt;p&gt;Once you have determined with 'top' that the system is waiting on IO-access,
It is nice to know&lt;/p&gt;
&lt;p&gt;which process is responsibe for this IO. Therefore, you want a list of
processes, just like top provides, but instead of CPU or RAM usage, it shows
the IO a process is generating. This is exactly what 'iotop' provides.&lt;/p&gt;
&lt;p&gt;This is ideal when troubleshooting performance problems caused by heavy IO.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://guichaz.free.fr/iotop/"&gt;http://guichaz.free.fr/iotop/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="iotop" src="http://guichaz.free.fr/iotop/iotop_small.png" /&gt;&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Making cowpatty recognize a four-way handshake</title><link href="https://louwrentius.com/making-cowpatty-recognize-a-four-way-handshake.html" rel="alternate"/><published>2009-11-22T12:52:00+01:00</published><updated>2009-11-22T12:52:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-22:/making-cowpatty-recognize-a-four-way-handshake.html</id><summary type="html">&lt;p&gt;I was unable to get cowpatty working with a packet capture that actually&lt;/p&gt;
&lt;p&gt;contains a four-way handshake of a WPA session.&lt;/p&gt;
&lt;p&gt;I got it working like this:&lt;/p&gt;
&lt;p&gt;First, download cowpatty &lt;a href="http://www.willhackforsushi.com/?page_id=50"&gt;4.6 right here&lt;/a&gt;, within the source directory of
cowpatty.&lt;/p&gt;
&lt;p&gt;Extract cowpatty and a&lt;a href="http://proton.cygnusx-1.org/~edgan/cowpatty/cowpatty-4.6-fixup14.patch"&gt;pply this patch&lt;/a&gt; using &lt;a href="http://forum.aircrack-"&gt;these instructions …&lt;/a&gt;&lt;/p&gt;</summary><content type="html">&lt;p&gt;I was unable to get cowpatty working with a packet capture that actually&lt;/p&gt;
&lt;p&gt;contains a four-way handshake of a WPA session.&lt;/p&gt;
&lt;p&gt;I got it working like this:&lt;/p&gt;
&lt;p&gt;First, download cowpatty &lt;a href="http://www.willhackforsushi.com/?page_id=50"&gt;4.6 right here&lt;/a&gt;, within the source directory of
cowpatty.&lt;/p&gt;
&lt;p&gt;Extract cowpatty and a&lt;a href="http://proton.cygnusx-1.org/~edgan/cowpatty/cowpatty-4.6-fixup14.patch"&gt;pply this patch&lt;/a&gt; using &lt;a href="http://forum.aircrack-"&gt;these instructions&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Then build couwpatty just with 'make' and 'make install'.&lt;/p&gt;
&lt;p&gt;I created a test setup with a known password. However, this patched&lt;/p&gt;
&lt;p&gt;version did not find the passphrase using a dictionary file.&lt;/p&gt;
&lt;p&gt;I then used genpmk to create a precomputed hash database like this:&lt;/p&gt;
&lt;p&gt;genpmk -f ./aircrack-ng-1.0/test/password.lst -d hashes -s default&lt;/p&gt;
&lt;p&gt;Please note that I added the correct passphrase to this password list to&lt;/p&gt;
&lt;p&gt;make sure that cowpatty works.&lt;/p&gt;
&lt;p&gt;Finally, using the -d option on the hash file, cowpatty&lt;/p&gt;
&lt;p&gt;managed to crack the PSK.&lt;/p&gt;
&lt;p&gt;ng.org/index.php?PHPSESSID=9e79f0ff83630bbe6c870b1a9aeef63c&amp;amp;topic=5867.0&lt;/p&gt;</content><category term="Uncategorized"/><category term="wpa"/><category term="cowpatty"/><category term="four-way"/><category term="handshake"/><category term="crack"/><category term="aircrack"/></entry><entry><title>Monitor power usage with your UPS</title><link href="https://louwrentius.com/monitor-power-usage-with-your-ups.html" rel="alternate"/><published>2009-11-18T21:09:00+01:00</published><updated>2009-11-18T21:09:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-18:/monitor-power-usage-with-your-ups.html</id><summary type="html">&lt;p&gt;If a system is connected to a UPS (Uninterruptible Power Supply), it is
possible to determine how much power it consumes. For this purpose, I wrote a
small script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt; Host:~# ./ups.sh

 UPS model: Back-UPS RS 1200 LCD
 APC model: Back-UPS RS 1200 LC
 Capacity: 720 Watt
 Load: 18 Percent …&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</summary><content type="html">&lt;p&gt;If a system is connected to a UPS (Uninterruptible Power Supply), it is
possible to determine how much power it consumes. For this purpose, I wrote a
small script:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt; Host:~# ./ups.sh

 UPS model: Back-UPS RS 1200 LCD
 APC model: Back-UPS RS 1200 LC
 Capacity: 720 Watt
 Load: 18 Percent
 Usage: 129 Watt
 Time left: 33 Minutes
 Status: ONLINE

 Host:~# ./ups.sh

 UPS model: Back-UPS RS 1200 LCD
 APC model: Back-UPS RS 1200 LC
 Capacity: 720 Watt
 Load: 19 Percent
 Usage: 136 Watt
 Time left: 22 Minutes
 Status: ONBATT
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;This script assumes that:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;You are running a unix&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;You run apcupsd&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The script can be downloaded &lt;a href="/files/ups.sh"&gt;here&lt;/a&gt;:&lt;/p&gt;</content><category term="Uncategorized"/><category term="Linux"/><category term="apcupsd"/><category term="ups"/><category term="script"/><category term="power"/><category term="usage"/></entry><entry><title>24 TB based on Norco RPC-4020 and Linux Software RAID</title><link href="https://louwrentius.com/24-tb-based-on-norco-rpc-4020-and-linux-software-raid.html" rel="alternate"/><published>2009-11-14T13:07:00+01:00</published><updated>2009-11-14T13:07:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-14:/24-tb-based-on-norco-rpc-4020-and-linux-software-raid.html</id><content type="html">&lt;p&gt;Just a quick link:&lt;/p&gt;
&lt;p&gt;Some person build basically the same setup, including identical controller,
providing 28 TB of storage: &lt;a href="http://www.hardforum.com/showthread.php?t=1393939&amp;amp;page=25"&gt;Take a look here&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The main difference is that this person uses 1.5 TB disk, thus achieving more
storage.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Debian Linux Preseeding - an installation framework</title><link href="https://louwrentius.com/debian-linux-preseeding-an-installation-framework.html" rel="alternate"/><published>2009-11-11T21:11:00+01:00</published><updated>2009-11-11T21:11:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-11:/debian-linux-preseeding-an-installation-framework.html</id><summary type="html">&lt;p&gt;Look Ma!&lt;/p&gt;
&lt;p&gt;No hands!&lt;/p&gt;
&lt;p&gt;just watching a system PXE-boot and install itself into a fully operational
system is fun. PXE boot and preseeding is not enough however to accomplish
this.&lt;/p&gt;
&lt;p&gt;By itself, preseeding only installs a basic operating system. Next, you need
to configure all sorts of things and services …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Look Ma!&lt;/p&gt;
&lt;p&gt;No hands!&lt;/p&gt;
&lt;p&gt;just watching a system PXE-boot and install itself into a fully operational
system is fun. PXE boot and preseeding is not enough however to accomplish
this.&lt;/p&gt;
&lt;p&gt;By itself, preseeding only installs a basic operating system. Next, you need
to configure all sorts of things and services, install additional software,
create accounts. etc.&lt;/p&gt;
&lt;p&gt;So there is a whole post-install process that you also need to automate.
Preseeding by itself, as I understand it, does not seem to be able to do that
for you. But you can execute commands at the end of the installation.&lt;/p&gt;
&lt;p&gt;First, I'd like to point out that the alternative to Debian preseeding is, in
my opinion, &lt;a href="http://www.informatik.uni-koeln.de/fai/"&gt;FAI or Fully Automated Installation&lt;/a&gt;. I want to make clear
that this is a product with a long history that may better suit your needs. I
do not use FAI because I find it way to complicated. It seems very powerful to
me, but I don't understand it.&lt;/p&gt;
&lt;p&gt;I understand preseeding and shell scripts. Putting commands that I would
otherwise execute manually are now performed by some shell script. And I think
every administrator understands shell scripts and will be able to automate
installation with almost no effort by just executing a bunch of shell scripts
that install various additional components.&lt;/p&gt;
&lt;p&gt;I wrote a small installation 'framework' that can be used in conjunction with
preseeding to truly fully automate your installation, without the requirement
of learning complex stuff like FAI.&lt;/p&gt;
&lt;p&gt;Unfortunately, it is not available yet on-line, but as soon as I find the
time, a new project will be started and this small installation framework will
be available with some example preseed configuration.&lt;/p&gt;
&lt;p&gt;In day-to-day operations I use this script to install servers and laptops.
Once you see it you will like it.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Linux Mac Mini - temperature monitoring with lm-sensors</title><link href="https://louwrentius.com/linux-mac-mini-temperature-monitoring-with-lm-sensors.html" rel="alternate"/><published>2009-11-09T01:21:00+01:00</published><updated>2009-11-09T01:21:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-09:/linux-mac-mini-temperature-monitoring-with-lm-sensors.html</id><summary type="html">&lt;p&gt;This post is about getting temperature monitoring to work with a Mac Mini
running Linux.&lt;/p&gt;
&lt;p&gt;Using Debian Lenny, out of the box, lm-sensors is not working. No sensors can
be found. This is how temperature monitoring and fan speed monitoring can be
made to work:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;modprobe applesmc&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you run …&lt;/p&gt;</summary><content type="html">&lt;p&gt;This post is about getting temperature monitoring to work with a Mac Mini
running Linux.&lt;/p&gt;
&lt;p&gt;Using Debian Lenny, out of the box, lm-sensors is not working. No sensors can
be found. This is how temperature monitoring and fan speed monitoring can be
made to work:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;modprobe applesmc&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you run "sensors-detect" after this, and do a:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;modprobe coretemp&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Then "sensors" will give you ouput like this:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Mini:/sys/devices/platform# sensors&lt;/p&gt;
&lt;p&gt;applesmc-isa-0300&lt;/p&gt;
&lt;p&gt;Adapter: ISA adapter&lt;/p&gt;
&lt;p&gt;Master : 2151 RPM (min = 1500 RPM)&lt;/p&gt;
&lt;p&gt;temp1: +83.2°C&lt;/p&gt;
&lt;p&gt;temp2: +68.0°C&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Some software to control the fan speed:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://stargate.solsys.org/mod.php?mod=faq&amp;amp;op=extlist&amp;amp;topicid=27&amp;amp;expan"&gt;http://stargate.solsys.org/mod.php?mod=faq&amp;amp;op=extlist&amp;amp;topicid=27&amp;amp;expand=yes#1
18&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;d=yes#118&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Linux on Mac Mini - boot after power failure</title><link href="https://louwrentius.com/linux-on-mac-mini-boot-after-power-failure.html" rel="alternate"/><published>2009-11-08T20:57:00+01:00</published><updated>2009-11-08T20:57:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-08:/linux-on-mac-mini-boot-after-power-failure.html</id><summary type="html">&lt;p&gt;When using a Mac Mini as a server or router, it is very nice if the machine
automatically boots if a power failure has occurred.&lt;/p&gt;
&lt;p&gt;User chirhoxi on the ubuntu forum found out how this can be achieved:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://ubuntuforums.org/showthread.php?t=1209576"&gt;http://ubuntuforums.org/showthread.php?t=1209576&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Basically you need one of …&lt;/p&gt;</summary><content type="html">&lt;p&gt;When using a Mac Mini as a server or router, it is very nice if the machine
automatically boots if a power failure has occurred.&lt;/p&gt;
&lt;p&gt;User chirhoxi on the ubuntu forum found out how this can be achieved:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://ubuntuforums.org/showthread.php?t=1209576"&gt;http://ubuntuforums.org/showthread.php?t=1209576&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Basically you need one of these commands:&lt;/p&gt;
&lt;p&gt;Original Mac Mini:&lt;/p&gt;
&lt;p&gt;setpci -s 00:03.0 0xa4.b=0&lt;/p&gt;
&lt;p&gt;Newer Mac Mini:&lt;/p&gt;
&lt;p&gt;setpci -s 00:03.0 0x7b.b=19&lt;/p&gt;
&lt;p&gt;These commands might not work with the latest Mac Minis but the thread
discusses how to determine for yourself what the appropriate command is.&lt;/p&gt;</content><category term="Uncategorized"/><category term="mac"/><category term="mini"/><category term="boot"/><category term="after"/><category term="power"/><category term="failure"/><category term="loss"/><category term="reboot"/></entry><entry><title>How to run Debian Linux on an Intel based Mac Mini</title><link href="https://louwrentius.com/how-to-run-debian-linux-on-an-intel-based-mac-mini.html" rel="alternate"/><published>2009-11-01T23:22:00+01:00</published><updated>2009-11-01T23:22:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-11-01:/how-to-run-debian-linux-on-an-intel-based-mac-mini.html</id><summary type="html">&lt;p&gt;The Mac Mini is just a gorgeous device. It is beautiful, small, silent,
powerfull yet energy efficient. When idle, it uses around 20 watts. I'm using
one of the first Intel-based Minis with an Intel Core Duo chip, running at 1.6
Ghz.&lt;/p&gt;
&lt;p&gt;I want to use this mini as …&lt;/p&gt;</summary><content type="html">&lt;p&gt;The Mac Mini is just a gorgeous device. It is beautiful, small, silent,
powerfull yet energy efficient. When idle, it uses around 20 watts. I'm using
one of the first Intel-based Minis with an Intel Core Duo chip, running at 1.6
Ghz.&lt;/p&gt;
&lt;p&gt;I want to use this mini as an expensive router and download host. I could have
used something embedded, such as one of those router boxes that costs about 70
euros, but no, I want to do some more with my router, such as downloading,
etc. It is the only device in my house that is allowed to run 24/7 so it has
to be a bit more powerful if I want more than just routing. I know that this
mini was like 600 euros or something back in the days, and that is quite some
money to spend on something that is now only a router. However, when I was
still running Mac OS X on it, I didn't do much more with it than I will now,
it will actually do more.&lt;/p&gt;
&lt;p&gt;I am assuming that you want to run Linux exclusively on the Mac and that Mac
OS X will be wiped off.&lt;/p&gt;
&lt;p&gt;To get this puppy running Debian Linux (Lenny), you need to first boot the Mac
with the (Snow) Leopard OS X boot CD and startup the diskutilily.&lt;/p&gt;
&lt;p&gt;You need to create at least two partitions: one for the root file system and
one for swap. The most important step is to select 'options' under the
partition layout screen, and select Master Boot Record partitioning instead of
the other 2 options. Do NOT use GUID or Apple Partition Map.&lt;/p&gt;
&lt;p&gt;&lt;img alt="image" src="https://louwrentius.files.com/2009/11/mbr.png?w=300" /&gt;&lt;/p&gt;
&lt;p&gt;Now, boot your regular Debian Linux boot CD, I use the regular network
installation CD. When you get to the partitioning screen, do NOT auto-
partition the hard disk. Just reconfigure the existing partitions you just
made using Diskutility. So the large partition will be configured as "/" and
made bootable. The small partition must be configured as swap.&lt;/p&gt;
&lt;p&gt;After the installation finishes, just install GRUB in the MBR and reboot. If
all went alright, you will see a non-blinking folder on a gray background for
a couple of seconds, after which Linux will boot. If you get a blinking gray
folder with a question mark, something went wrong.&lt;/p&gt;
&lt;p&gt;It seems that if configured properly, after the EFI boot mechanism fails to
find a system folder on some Mac partition, the legacy BIOS emulation seems to
kick in, and star to search for something to boot.&lt;/p&gt;
&lt;p&gt;The Mini has only one network card, so another one is necessary to run it as a
router. I bought some no brand USB2 to 100 MBIT NIC (Bus 005 Device 003: ID
9710:7830 MosChip Semiconductor MCS7830 Ethernet) which seems to run smoothly.&lt;/p&gt;
&lt;p&gt;card with a dual &lt;a href="http://www.globalamericaninc.com/p1507790/1507790_-__Mini-"&gt;gigabit card&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I guess you will need to mod the Mini but it will allow true gigabit speeds on
all interfaces.&lt;/p&gt;
&lt;p&gt;PCI_Express_Dual_Gigabit_LAN_Module/product_info.html&lt;/p&gt;</content><category term="Uncategorized"/><category term="Debian"/><category term="Linux"/><category term="Lenny"/><category term="Mac"/><category term="Mini"/><category term="EFI"/><category term="Disk"/><category term="utility"/><category term="Master"/><category term="Boot"/><category term="Record"/></entry><entry><title>PPSS version 2.30 now operates asynchronous</title><link href="https://louwrentius.com/ppss-version-230-now-operates-asynchronous.html" rel="alternate"/><published>2009-09-26T19:32:00+02:00</published><updated>2009-09-26T19:32:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-09-26:/ppss-version-230-now-operates-asynchronous.html</id><summary type="html">&lt;p&gt;If you background a bash or shell process, how do you determine if it has
finished? Since inter process communication is not possible using shell
scripts, people often refer to while loops or other polling mechanisms to
determine if some process has stopped.&lt;/p&gt;
&lt;p&gt;However, the one player that knows best …&lt;/p&gt;</summary><content type="html">&lt;p&gt;If you background a bash or shell process, how do you determine if it has
finished? Since inter process communication is not possible using shell
scripts, people often refer to while loops or other polling mechanisms to
determine if some process has stopped.&lt;/p&gt;
&lt;p&gt;However, the one player that knows best if a process has finished is the
process itself. So if only this process could tell the parent or other process
about this...&lt;/p&gt;
&lt;p&gt;The solution is using a FIFO or 'pipe'. A listener process reads the pipe and
executes a command for every message received through this pipe. This was
already build-in into PPSS. However, PPSS had this dirty while loop that polls
every x seconds to determine if there are still running workers. If not, PPSS
finishes itself.&lt;/p&gt;
&lt;p&gt;However, while loops and polling mechanisms are evil, dirty and bad. The
nicest solution is to make PPSS fully asynchronous. To achieve this, every job
must tell PPSS that is has finished. PPSS already has this listening process
that listens to the pipe for commands. If this channel is used by workers to
communicate that a worker is finished, PPSS will know when all workers are
finished.&lt;/p&gt;
&lt;p&gt;This makes PPSS a lot faster and responsive.&lt;/p&gt;</content><category term="Uncategorized"/><category term="bash"/><category term="inter"/><category term="process"/><category term="communication"/><category term="asynchronous"/><category term="FIFO"/></entry><entry><title>How to build an energy efficient computer for home use</title><link href="https://louwrentius.com/how-to-build-an-energy-efficient-computer-for-home-use.html" rel="alternate"/><published>2009-09-19T19:17:00+02:00</published><updated>2009-09-19T19:17:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-09-19:/how-to-build-an-energy-efficient-computer-for-home-use.html</id><summary type="html">&lt;p&gt;In short:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Buy whatever you fucking want.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Turn the fucking thing off when you're not using it.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Long:&lt;/p&gt;
&lt;p&gt;People are spending a lot of time building an energy efficient home computer,
that can act as an HTPC, NAS, or whatever. It must consume as little power as
possible, because it …&lt;/p&gt;</summary><content type="html">&lt;p&gt;In short:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Buy whatever you fucking want.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Turn the fucking thing off when you're not using it.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Long:&lt;/p&gt;
&lt;p&gt;People are spending a lot of time building an energy efficient home computer,
that can act as an HTPC, NAS, or whatever. It must consume as little power as
possible, because it it will be on 24/7.&lt;/p&gt;
&lt;p&gt;Why the fuck do you want to leave a system on 24/7 at home?&lt;/p&gt;
&lt;p&gt;Unless you're unemployed you will be at work most of the time. And during that
time, this machine is doing absolutely nothing.&lt;/p&gt;
&lt;p&gt;There may only be one system that stays on 24/7 and that is your router,
either some embedded router thingy or something based on a low-power PC, but
that's about it. Turn every thing else off.&lt;/p&gt;
&lt;p&gt;A machine that does 200 Watt idle that is only turned on when necessary will
be more energy efficient than your specially build 40 watt NAS or whatever it
is that is running 24/7. Nothing can beat a system that is turned off.&lt;/p&gt;
&lt;p&gt;If you need a system, just use wake-on-lan or WOL to turn the damn thing on.
It will be ready in about 2 or 3 minutes and then you can do whatever you
want.&lt;/p&gt;
&lt;p&gt;Fine if you leave a system on that is downloading some stuff during the night
or day, but after the download has finished, turn the damn thing off.&lt;/p&gt;
&lt;p&gt;If you're honest with yourself and really think about it, there is no need to
keep a system on for 24/7. I know you may come up with excuses, but remember
that you still can use your router for that.&lt;/p&gt;
&lt;p&gt;By the way, if you're searching for a really energy efficient computer, buy a
Mac Mini. Although quite expensive if you ask me, the're doing 30 watt in idle
and almost nothing when sleeping. And if a mac is asleep, it can be woken with
WOL and is up in seconds. They make an excelent download server.&lt;/p&gt;
&lt;p&gt;[EDIT]&lt;/p&gt;
&lt;p&gt;There is also the option of S3 or S4 under Linux: suspend to ram or disk.
However, your mileage may vary. If it works for you your system will be down
and up in seconds. However, my experience is that it very much depends on your
hardware if this will work. My Highpoint cards do not seem to like it, my
array does not awake and the screen of the system stays blank.&lt;/p&gt;
&lt;p&gt;If it works, it is a faster solution than just to turn the system off and on
with WOL. My experience is that is seems not that robust.&lt;/p&gt;</content><category term="Uncategorized"/><category term="energy"/><category term="efficient"/><category term="home"/><category term="server"/><category term="nas"/><category term="htpc"/><category term="router"/><category term="24/7"/><category term="wake"/><category term="on"/><category term="lan"/><category term="wol"/></entry><entry><title>Visual representation of hard drives and their temperature</title><link href="https://louwrentius.com/visual-representation-of-hard-drives-and-their-temperature.html" rel="alternate"/><published>2009-09-12T23:53:00+02:00</published><updated>2009-09-12T23:53:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-09-12:/visual-representation-of-hard-drives-and-their-temperature.html</id><summary type="html">&lt;blockquote&gt;
&lt;p&gt;If you build a NAS with many drives, it may be of interest to you which
drives get hot and where they are located in the chassis. My Norco 4020 case
has twenty drives in RAID 6, plus two operating system drives in RAID 1. I
wrote a script that …&lt;/p&gt;&lt;/blockquote&gt;</summary><content type="html">&lt;blockquote&gt;
&lt;p&gt;If you build a NAS with many drives, it may be of interest to you which
drives get hot and where they are located in the chassis. My Norco 4020 case
has twenty drives in RAID 6, plus two operating system drives in RAID 1. I
wrote a script that shows me the temperature of each drive, positioned in such
a way that it represents the actual physical location of the drive in the
chassis:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt; -- 30 -- | -- 27 --
 | 26 | 27 | 28 | 25 |
 | 30 | 32 | 30 | 29 |
 | 31 | 33 | 33 | 29 |
 | 33 | 32 | 35 | 30 |
 | 32 | 34 | 35 | 31 |
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;In this example, you can determine that the top drives seem to stay the
coolest. The center and lower drives get hotter.&lt;/p&gt;
&lt;p&gt;If you want to use this script, you will have to change it for your own
specific setup. You can get it &lt;a href="/files/show-hdd-temp.tgz"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;This visual representation would also be nice to identify which drive has
failed and where it is located in the chassis.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'Linux: obtain motherboard model / type and vendor'</title><link href="https://louwrentius.com/linux-obtain-motherboard-model-type-and-vendor.html" rel="alternate"/><published>2009-08-30T21:16:00+02:00</published><updated>2009-08-30T21:16:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-08-30:/linux-obtain-motherboard-model-type-and-vendor.html</id><summary type="html">&lt;p&gt;If you want to know what motherboard is installed in a system, use the tool
dmidecode:&lt;/p&gt;
&lt;p&gt;dmidecode | grep -e "Manufacturer|Product" | head -n 4 | tail -n 2&lt;/p&gt;
&lt;p&gt;The result might be something like:&lt;/p&gt;
&lt;p&gt;Manufacturer: ASUSTeK Computer INC.&lt;/p&gt;
&lt;p&gt;Product Name: P5Q-EM DO&lt;/p&gt;
&lt;p&gt;Manufacturer: ASUSTeK Computer INC.&lt;/p&gt;
&lt;p&gt;Product Name: P6T DELUXE&lt;/p&gt;
&lt;p&gt;Manufacturer …&lt;/p&gt;</summary><content type="html">&lt;p&gt;If you want to know what motherboard is installed in a system, use the tool
dmidecode:&lt;/p&gt;
&lt;p&gt;dmidecode | grep -e "Manufacturer|Product" | head -n 4 | tail -n 2&lt;/p&gt;
&lt;p&gt;The result might be something like:&lt;/p&gt;
&lt;p&gt;Manufacturer: ASUSTeK Computer INC.&lt;/p&gt;
&lt;p&gt;Product Name: P5Q-EM DO&lt;/p&gt;
&lt;p&gt;Manufacturer: ASUSTeK Computer INC.&lt;/p&gt;
&lt;p&gt;Product Name: P6T DELUXE&lt;/p&gt;
&lt;p&gt;Manufacturer: ASUSTeK Computer INC.&lt;/p&gt;
&lt;p&gt;Product Name: M2A-VM&lt;/p&gt;
&lt;p&gt;Manufacturer: Apple Computer, Inc.&lt;/p&gt;
&lt;p&gt;Product Name: Mac-F4208EC8&lt;/p&gt;
&lt;p&gt;Manufacturer: Compaq&lt;/p&gt;
&lt;p&gt;Product Name: 0688h&lt;/p&gt;</content><category term="Uncategorized"/><category term="Linuxmanufacturermodelmotherboardtypevendor"/></entry><entry><title>'lm-sensors: hardware monitoring with the w83627ehf module'</title><link href="https://louwrentius.com/lm-sensors-hardware-monitoring-with-the-w83627ehf-module.html" rel="alternate"/><published>2009-08-30T16:26:00+02:00</published><updated>2009-08-30T16:26:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-08-30:/lm-sensors-hardware-monitoring-with-the-w83627ehf-module.html</id><summary type="html">&lt;p&gt;I have two systems that use the w83627ehf driver for hardware monitoring.
However, if this driver is installed with a regular modprobe like:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;modprobe w83627ehf
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The result will be:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;FATAL&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Error&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;inserting&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;w83627ehf&lt;/span&gt;
&lt;span class="o"&gt;(/&lt;/span&gt;&lt;span class="n"&gt;lib&lt;/span&gt;&lt;span class="sr"&gt;/modules/2.6.28-1-amd64/kernel/drivers/hwmon/&lt;/span&gt;&lt;span class="n"&gt;w83627ehf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;ko&lt;/span&gt;&lt;span class="o"&gt;):&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;No&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;such&lt;/span&gt;
&lt;span class="n"&gt;device&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;I had this issue …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I have two systems that use the w83627ehf driver for hardware monitoring.
However, if this driver is installed with a regular modprobe like:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;modprobe w83627ehf
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The result will be:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;FATAL&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Error&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;inserting&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;w83627ehf&lt;/span&gt;
&lt;span class="o"&gt;(/&lt;/span&gt;&lt;span class="n"&gt;lib&lt;/span&gt;&lt;span class="sr"&gt;/modules/2.6.28-1-amd64/kernel/drivers/hwmon/&lt;/span&gt;&lt;span class="n"&gt;w83627ehf&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;ko&lt;/span&gt;&lt;span class="o"&gt;):&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;No&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;such&lt;/span&gt;
&lt;span class="n"&gt;device&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;I had this issue with the following mainboards:&lt;/p&gt;
&lt;p&gt;Asus P5Q-EM DO (Core 2 duo)
Asus: P6T deluxe (Core 7i)&lt;/p&gt;
&lt;p&gt;The solution is simple, as I found after googling for some time:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;modprobe w83627ehf force_id=0x8860
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;The result:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;w83627ehf-isa-0290
Adapter: ISA adapter
VCore: +0.88 V (min = +0.00 V, max = +1.74 V)
in1: +11.67 V (min = +0.00 V, max = +5.49 V) ALARM
AVCC: +3.34 V (min = +0.40 V, max = +0.03 V) ALARM
3VCC: +3.31 V (min = +1.15 V, max = +0.58 V) ALARM
in4: +1.65 V (min = +0.54 V, max = +0.22 V) ALARM
in5: +2.04 V (min = +0.71 V, max = +0.11 V) ALARM
in6: +3.79 V (min = +0.10 V, max = +2.30 V) ALARM
VSB: +3.38 V (min = +0.45 V, max = +2.43 V) ALARM
VBAT: +3.30 V (min = +0.67 V, max = +0.77 V) ALARM
in9: +0.00 V (min = +1.10 V, max = +0.57 V) ALARM
Case Fan: 0 RPM (min = 104 RPM, div = 128) ALARM
CPU Fan: 0 RPM (min = 42187 RPM, div = 32) ALARM
Aux Fan: 0 RPM (min = 162 RPM, div = 128) ALARM
fan4: 0 RPM (min = 42187 RPM, div = 32) ALARM
fan5: 0 RPM (min = 42187 RPM, div = 32) ALARM
Sys Temp: +40.0°C (high = +4.0°C, hyst = +0.0°C) ALARM sensor = thermistor
CPU Temp: +42.0°C (high = +80.0°C, hyst = +75.0°C) sensor = diode
AUX Temp: +30.5°C (high = +80.0°C, hyst = +75.0°C) sensor = thermistor
cpu0_vid: +0.000 V
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Using ncat to provide SSL-support to non-ssl capable software</title><link href="https://louwrentius.com/using-ncat-to-provide-ssl-support-to-non-ssl-capable-software.html" rel="alternate"/><published>2009-08-21T15:49:00+02:00</published><updated>2009-08-21T15:49:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-08-21:/using-ncat-to-provide-ssl-support-to-non-ssl-capable-software.html</id><summary type="html">&lt;p&gt;Sometimes, people are using software that does not support encrypted
connections using SSL. To provide SSL-support to such a client, ncat can be
used. Ncat is part of nmap, the famous port-scanner.&lt;/p&gt;
&lt;p&gt;The main principle is that the non-ssl capable software does not connect to
the SSL-based service, but to …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Sometimes, people are using software that does not support encrypted
connections using SSL. To provide SSL-support to such a client, ncat can be
used. Ncat is part of nmap, the famous port-scanner.&lt;/p&gt;
&lt;p&gt;The main principle is that the non-ssl capable software does not connect to
the SSL-based service, but to the local host. Ncat will be listening on the
localhost and will setup an SSL-connection with the SSL-based service on
behalf of the non-ssl capable software.&lt;/p&gt;
&lt;p&gt;This simple command allows an application to browse to port 80, and perform
regular HTTP-request, while in fact, they are encapsulated within a SSL-
connection:&lt;/p&gt;
&lt;p&gt;ncat -l 80 -c "ncat (ip-address) (port) --ssl"&lt;/p&gt;
&lt;p&gt;The -l option specifies the local port on which the SSL-tunnel will be
listening. The ip-address and port refer to the SSL-based service.&lt;/p&gt;
&lt;p&gt;So if the client connects to 127.0.0.1 on port 80 it will actually connect
through the SSL-tunnel to the external service.&lt;/p&gt;
&lt;p&gt;Often stunnel is used for this job but this software craps out on debian Etch
with some error like:&lt;/p&gt;
&lt;p&gt;SSL routines:SSL3_GET_RECORD:bad decompression&lt;/p&gt;
&lt;p&gt;But ncat is an excellent alternative.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Howto get the hard disk size under Linux?</title><link href="https://louwrentius.com/howto-get-the-hard-disk-size-under-linux.html" rel="alternate"/><published>2009-08-18T21:19:00+02:00</published><updated>2009-08-18T21:19:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-08-18:/howto-get-the-hard-disk-size-under-linux.html</id><summary type="html">&lt;p&gt;A: There is no single tool for this job, but it seems that Fdisk is just fine:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;server:~# fdisk -l 2&amp;gt; /dev/null | grep Disk | grep -v identifier&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Disk /dev/sda: 500.0 GB, 500028145664 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdb: 500.0 GB, 500028145664 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdc: 1000.1 GB …&lt;/p&gt;</summary><content type="html">&lt;p&gt;A: There is no single tool for this job, but it seems that Fdisk is just fine:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;server:~# fdisk -l 2&amp;gt; /dev/null | grep Disk | grep -v identifier&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Disk /dev/sda: 500.0 GB, 500028145664 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdb: 500.0 GB, 500028145664 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdc: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdd: 500.0 GB, 500028145664 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sde: 500.0 GB, 500028145664 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/hda: 80.0 GB, 80026361856 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/md5: 1500.0 GB, 1500084240384 bytes&lt;/p&gt;
&lt;p&gt;The nice thing about using fdisk is that it automatically lists the size of
all block devices.&lt;/p&gt;
&lt;p&gt;Here is a list of my NAS, mentioned earlier.&lt;/p&gt;
&lt;p&gt;Beast:~# fdisk -l 2&amp;gt; /dev/null | grep Disk | grep -v identifier&lt;/p&gt;
&lt;p&gt;Disk /dev/sda: 60.0 GB, 60011642880 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdb: 60.0 GB, 60011642880 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdc: 1000.2 GB, 1000204886016 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdd: 1000.2 GB, 1000204886016 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sde: 1000.2 GB, 1000204886016 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdf: 1000.2 GB, 1000204886016 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/md0: 57.9 GB, 57996345344 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/md1: 2015 MB, 2015100928 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdg: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdh: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdi: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdj: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdk: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdl: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdm: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdn: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdo: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdp: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdq: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdr: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sds: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdt: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdu: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/sdv: 1000.1 GB, 1000123400192 bytes&lt;/p&gt;
&lt;p&gt;Disk /dev/md5: 18002.2 GB, 18002220023808 bytes&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>HighPoint RocketRAID and staggered spinup with Samsung F1</title><link href="https://louwrentius.com/highpoint-rocketraid-and-staggered-spinup-with-samsung-f1.html" rel="alternate"/><published>2009-07-21T20:13:00+02:00</published><updated>2009-07-21T20:13:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-07-21:/highpoint-rocketraid-and-staggered-spinup-with-samsung-f1.html</id><summary type="html">&lt;p&gt;I have experienced problems using a HighPoint RocketRaid 2320 and 2340 when
they are using 'staggered spinup' in combination with Samsung Spinpoint F1, 1
(one) terrabyte disks.&lt;/p&gt;
&lt;p&gt;The problem is that the F1 disks spinup very slowly and often seem to 'hang'
while making ticking noises that will scare any …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I have experienced problems using a HighPoint RocketRaid 2320 and 2340 when
they are using 'staggered spinup' in combination with Samsung Spinpoint F1, 1
(one) terrabyte disks.&lt;/p&gt;
&lt;p&gt;The problem is that the F1 disks spinup very slowly and often seem to 'hang'
while making ticking noises that will scare any computer user to death. When,
after ages, you have the luck that no disks keeps hanging during startup, the
first thing to do is to disable staggered spinup.&lt;/p&gt;
&lt;p&gt;However, if staggered spinup is not used and all disks will spinup together,
please note that you will need a strong PSU to handle the short peak load. For
example, starting up 20 (twenty) disks will briefly generate a load of 550
Watt on my APC ups, according to its display.&lt;/p&gt;
&lt;p&gt;I estimate that during startup, each disk is roughly consuming 20 Watt. Take
this all into account when deciding which type of disks and controllers you
will be using.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>8 TB RAID 6 Linux software RAID using EXT4</title><link href="https://louwrentius.com/8-tb-raid-6-linux-software-raid-using-ext4.html" rel="alternate"/><published>2009-07-05T22:45:00+02:00</published><updated>2009-07-05T22:45:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-07-05:/8-tb-raid-6-linux-software-raid-using-ext4.html</id><summary type="html">&lt;p&gt;Mobo: Asus P5Q-EM DO ( 6x sata)&lt;/p&gt;
&lt;p&gt;CPU: Core 2 Duo E7400&lt;/p&gt;
&lt;p&gt;RAM: 4 GB&lt;/p&gt;
&lt;p&gt;Controller; HighPoint RocketRAID 2314 (16x poorten)&lt;/p&gt;
&lt;p&gt;PSU: CooMas Silent Pro M 600W ATX2 (definitely not overkill)&lt;/p&gt;
&lt;p&gt;HD: Samsung 1 TB SAT2 HD103UJ (10x)&lt;/p&gt;
&lt;p&gt;OS: Debian Lenny with custom kernel (backported)&lt;/p&gt;
&lt;p&gt;FS: EXT4&lt;/p&gt;
&lt;p&gt;RAID config: &lt;strong&gt;10 disk …&lt;/strong&gt;&lt;/p&gt;</summary><content type="html">&lt;p&gt;Mobo: Asus P5Q-EM DO ( 6x sata)&lt;/p&gt;
&lt;p&gt;CPU: Core 2 Duo E7400&lt;/p&gt;
&lt;p&gt;RAM: 4 GB&lt;/p&gt;
&lt;p&gt;Controller; HighPoint RocketRAID 2314 (16x poorten)&lt;/p&gt;
&lt;p&gt;PSU: CooMas Silent Pro M 600W ATX2 (definitely not overkill)&lt;/p&gt;
&lt;p&gt;HD: Samsung 1 TB SAT2 HD103UJ (10x)&lt;/p&gt;
&lt;p&gt;OS: Debian Lenny with custom kernel (backported)&lt;/p&gt;
&lt;p&gt;FS: EXT4&lt;/p&gt;
&lt;p&gt;RAID config: &lt;strong&gt;10 disk RAID 6&lt;/strong&gt; based on Linux software RAID.&lt;/p&gt;
&lt;p&gt;Performance: &lt;strong&gt;Read: 850 MB/s Write: 300 MB/s&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Capacity: 7,5 GiB or 8 GB.&lt;/p&gt;
&lt;p&gt;I am very pleased with the result. Points that should be improved are the
temperature and noise. The PSU is a major overkill since this puppy draws less
than 200 watt.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://members.multiweb.nl/nan1/img/norco03.jpg"&gt;&lt;img alt="image" src="http://members.multiweb.nl/nan1/img/norco03.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://members.multiweb.nl/nan1/img/norco02.jpg"&gt;&lt;img alt="image" src="http://members.multiweb.nl/nan1/img/norco02.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Bunny:~# ./show-hdd-temp.sh&lt;/p&gt;
&lt;p&gt;Device  Temperature&lt;/p&gt;
&lt;p&gt;/dev/sda  32&lt;/p&gt;
&lt;p&gt;/dev/sdb  34&lt;/p&gt;
&lt;p&gt;/dev/sdc  33&lt;/p&gt;
&lt;p&gt;/dev/sdd  36&lt;/p&gt;
&lt;p&gt;/dev/sde  34&lt;/p&gt;
&lt;p&gt;/dev/sdf  33&lt;/p&gt;
&lt;p&gt;/dev/sdg  38&lt;/p&gt;
&lt;p&gt;/dev/sdh  39&lt;/p&gt;
&lt;p&gt;/dev/sdi  37&lt;/p&gt;
&lt;p&gt;/dev/sdj  36&lt;/p&gt;
&lt;p&gt;/dev/sdk  35&lt;/p&gt;
&lt;p&gt;Personalities : [raid6] [raid5] [raid4]&lt;/p&gt;
&lt;p&gt;md0 : active raid6 sdj[10] sdb[0] sdl[9] sdk[8] sdg[7] sdf[6] sdi[5] sdh[4]
sde[3] sdd&lt;a href="http://members.multiweb.nl/nan1/img/norco02.jpg"&gt;2&lt;/a&gt; sdc&lt;a href="http://members.multiweb.nl/nan1/img/norco03.jpg"&gt;1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;7813463552 blocks super 0.91 level 6, 64k chunk, algorithm 2 [11/11]
[UUUUUUUUUUU]&lt;/p&gt;
&lt;p&gt;[======&amp;gt;..............] reshape = 30.1% (294904524/976682944) finish=585.3min
speed=19413K/sec&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Linux RAID 6 performance using software RAID</title><link href="https://louwrentius.com/linux-raid-6-performance-using-software-raid.html" rel="alternate"/><published>2009-06-28T19:32:00+02:00</published><updated>2009-06-28T19:32:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-06-28:/linux-raid-6-performance-using-software-raid.html</id><summary type="html">&lt;p&gt;So after toying around with RAID 0 just for fun, time to get serious. I
created a RAID 6 of 10 x 1 TB disks. This gives me raw device &lt;strong&gt;&lt;em&gt;read speeds
of 850 MB/s&lt;/em&gt;&lt;/strong&gt; and &lt;strong&gt;&lt;em&gt;write speeds of 300 MB/s&lt;/em&gt;&lt;/strong&gt;. I think this is exactly
what should …&lt;/p&gt;</summary><content type="html">&lt;p&gt;So after toying around with RAID 0 just for fun, time to get serious. I
created a RAID 6 of 10 x 1 TB disks. This gives me raw device &lt;strong&gt;&lt;em&gt;read speeds
of 850 MB/s&lt;/em&gt;&lt;/strong&gt; and &lt;strong&gt;&lt;em&gt;write speeds of 300 MB/s&lt;/em&gt;&lt;/strong&gt;. I think this is exactly
what should be expected, but boy it is damn fast. Especially the write speed
surprises me.&lt;/p&gt;
&lt;p&gt;Still, if I format the device using EXT4, write speed stays the same. However,
read speed drop to about 350 MB/s. I don't understand why. Maybe some
misalignment? I don't know.&lt;/p&gt;
&lt;p&gt;The issue with the dropped read speed is due to an incorrect chunk size of the
array. The array now consists of 20 drives, providing 18 TB of storage using
XFS. Read speads exceed 1.1 GB/s (that is not a typo) and write speeds are
about 350 MB/s.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>1.0 GB/s using Linux software RAID</title><link href="https://louwrentius.com/10-gbs-using-linux-software-raid.html" rel="alternate"/><published>2009-06-26T23:58:00+02:00</published><updated>2009-06-26T23:58:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-06-26:/10-gbs-using-linux-software-raid.html</id><summary type="html">&lt;blockquote&gt;
&lt;p&gt;I filled the Norco case with hardware. It is now up and running, based on
Debian Linux (Lenny).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I immediately performed some initial tests with software RAID 0. The results
are just astounding.&lt;/p&gt;
&lt;p&gt;debian:~# dd if=/dev/md0 of=/dev/null bs=1M count=50000&lt;/p&gt;
&lt;p&gt;50000+0 records in&lt;/p&gt;
&lt;p&gt;50000 …&lt;/p&gt;</summary><content type="html">&lt;blockquote&gt;
&lt;p&gt;I filled the Norco case with hardware. It is now up and running, based on
Debian Linux (Lenny).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I immediately performed some initial tests with software RAID 0. The results
are just astounding.&lt;/p&gt;
&lt;p&gt;debian:~# dd if=/dev/md0 of=/dev/null bs=1M count=50000&lt;/p&gt;
&lt;p&gt;50000+0 records in&lt;/p&gt;
&lt;p&gt;50000+0 records out&lt;/p&gt;
&lt;p&gt;52428800000 bytes (52 GB) copied, 50.9222 s, 1.0 GB/s&lt;/p&gt;
&lt;p&gt;This is correct. &lt;strong&gt;1 Gigabyte per second&lt;/strong&gt; using 10 Samsung Spinpoint F1's
connected to the motherboard (4) and to the Highpoint Rocketraid 2340 (6).&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Bash Shell Function Library (BSFL) released.</title><link href="https://louwrentius.com/bash-shell-function-library-bsfl-released.html" rel="alternate"/><published>2009-05-31T20:22:00+02:00</published><updated>2009-05-31T20:22:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-05-31:/bash-shell-function-library-bsfl-released.html</id><summary type="html">&lt;p&gt;The Bash Shell Function Library (BSFL) is a small Bash script that acts as a
library for bash scripts. It provides a couple of functions that makes the
lives of most people using shell scripts a bit easier.&lt;a href="http://members.multiweb.nl/nan1/img/bsfl1.png"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://members.multiweb.nl/nan1/img/bsfl2.png"&gt;&lt;img alt="image" src="http://members.multiweb.nl/nan1/img/bsfl2.png" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The purpose of this library is to provide pre-build functions for actions …&lt;/p&gt;</summary><content type="html">&lt;p&gt;The Bash Shell Function Library (BSFL) is a small Bash script that acts as a
library for bash scripts. It provides a couple of functions that makes the
lives of most people using shell scripts a bit easier.&lt;a href="http://members.multiweb.nl/nan1/img/bsfl1.png"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://members.multiweb.nl/nan1/img/bsfl2.png"&gt;&lt;img alt="image" src="http://members.multiweb.nl/nan1/img/bsfl2.png" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The purpose of this library is to provide pre-build functions for actions that
often need to be performed, focussing on error-checking and logging. In this
example, a test-script is written that demonstrates the functions the library
provides.&lt;/p&gt;
&lt;p&gt;The project can be found at &lt;a href="http://code.google.com/p/bsfl/"&gt;this location.&lt;/a&gt;&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>'Tip of the day for every Linux or Unix user: brace expantion'</title><link href="https://louwrentius.com/tip-of-the-day-for-every-linux-or-unix-user-brace-expantion.html" rel="alternate"/><published>2009-05-02T22:24:00+02:00</published><updated>2009-05-02T22:24:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-05-02:/tip-of-the-day-for-every-linux-or-unix-user-brace-expantion.html</id><summary type="html">&lt;p&gt;Searching the web I discovered some really nice feature of the unix shell,
which I didn't know about.&lt;/p&gt;
&lt;p&gt;Try this:&lt;/p&gt;
&lt;p&gt;touch foobar.conf&lt;/p&gt;
&lt;p&gt;Now try this:&lt;/p&gt;
&lt;p&gt;cp foobar.conf{,.bak}&lt;/p&gt;
&lt;p&gt;It is equivalent to:&lt;/p&gt;
&lt;p&gt;cp foobar.conf foobar.conf.bak&lt;/p&gt;
&lt;p&gt;This is also the easiest way to create sequences. Do …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Searching the web I discovered some really nice feature of the unix shell,
which I didn't know about.&lt;/p&gt;
&lt;p&gt;Try this:&lt;/p&gt;
&lt;p&gt;touch foobar.conf&lt;/p&gt;
&lt;p&gt;Now try this:&lt;/p&gt;
&lt;p&gt;cp foobar.conf{,.bak}&lt;/p&gt;
&lt;p&gt;It is equivalent to:&lt;/p&gt;
&lt;p&gt;cp foobar.conf foobar.conf.bak&lt;/p&gt;
&lt;p&gt;This is also the easiest way to create sequences. Do not use 'seq' since you
cannot rely on it being installed.&lt;/p&gt;
&lt;p&gt;bash-3.2$ echo {1..10}&lt;/p&gt;
&lt;p&gt;1 2 3 4 5 6 7 8 9 10&lt;/p&gt;
&lt;p&gt;Please visit &lt;a href="http://f241vc15.com/2008/02/29/doing-cool-things-in-bash-and-in-linux/"&gt;this location&lt;/a&gt; for additional examples.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Compatibility Highpoint RocketRAID 2320 and Samsung Spinpoint F1</title><link href="https://louwrentius.com/compatibility-highpoint-rocketraid-2320-and-samsung-spinpoint-f1.html" rel="alternate"/><published>2009-04-26T22:38:00+02:00</published><updated>2009-04-26T22:38:00+02:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-04-26:/compatibility-highpoint-rocketraid-2320-and-samsung-spinpoint-f1.html</id><summary type="html">&lt;p&gt;There are some reports about incompatibility between RAID controllers and
Samsung Spinpoint F1 drives. I have no troubles with my 0.5 and 1.0 TB drives
from Samsung using mentioned controller. See below:&lt;/p&gt;
&lt;p&gt;Controller 1: RocketRAID 232x SATA Controller&lt;/p&gt;
&lt;p&gt;1/1/1 SAMSUNG HD103UJ 1000123MB, Normal&lt;/p&gt;
&lt;p&gt;1/2/1 …&lt;/p&gt;</summary><content type="html">&lt;p&gt;There are some reports about incompatibility between RAID controllers and
Samsung Spinpoint F1 drives. I have no troubles with my 0.5 and 1.0 TB drives
from Samsung using mentioned controller. See below:&lt;/p&gt;
&lt;p&gt;Controller 1: RocketRAID 232x SATA Controller&lt;/p&gt;
&lt;p&gt;1/1/1 SAMSUNG HD103UJ 1000123MB, Normal&lt;/p&gt;
&lt;p&gt;1/2/1 SAMSUNG HD103UJ 1000123MB, Normal&lt;/p&gt;
&lt;p&gt;1/3/1 SAMSUNG HD103UJ 1000123MB, Normal&lt;/p&gt;
&lt;p&gt;1/4/1 SAMSUNG HD103UJ 1000123MB, Normal&lt;/p&gt;
&lt;p&gt;1/5/1 SAMSUNG HD501LJ 500028MB, Normal&lt;/p&gt;
&lt;p&gt;1/6/1 SAMSUNG HD501LJ 500028MB, Normal&lt;/p&gt;
&lt;p&gt;1/7/1 SAMSUNG HD501LJ 500028MB, Normal&lt;/p&gt;
&lt;p&gt;1/8/1 SAMSUNG HD501LJ 500028MB, Normal&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Distributed Parallel Processing Shell Script (PPSS) released</title><link href="https://louwrentius.com/distributed-parallel-processing-shell-script-ppss-released.html" rel="alternate"/><published>2009-03-12T22:05:00+01:00</published><updated>2009-03-12T22:05:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2009-03-12:/distributed-parallel-processing-shell-script-ppss-released.html</id><summary type="html">&lt;p&gt;I'd like to announce the release of the distributed version of the Parallel
Processing Shell Script (&lt;a href="http://code.google.com/p/ppss"&gt;PPSS&lt;/a&gt;). PPSS is a bash script that allows you to
run commands in parallel. It is written to make use of current multi-core
CPUs.&lt;/p&gt;
&lt;p&gt;The new distributed version of PPSS allows you to run …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I'd like to announce the release of the distributed version of the Parallel
Processing Shell Script (&lt;a href="http://code.google.com/p/ppss"&gt;PPSS&lt;/a&gt;). PPSS is a bash script that allows you to
run commands in parallel. It is written to make use of current multi-core
CPUs.&lt;/p&gt;
&lt;p&gt;The new distributed version of PPSS allows you to run PPSS on multiple hosts,
that simultaneously work on a single group of files or other items. A central
server is used for file locking. This way, nodes know which files are 'locked'
by other nodes and/or have already been processed.&lt;/p&gt;
&lt;p&gt;PPSS is written to be very easy to use. You can be up and running on a single
host within 5 minutes. Distributed usage requires the (one-time) setup of some
SSH accounts on your nodes and server, but that's about it. Please take a look
at distributed PPSS for yourself at:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://code.google.com/p/ppss"&gt;http://code.google.com/p/ppss&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I used distributed PPSS to encode 400 GB of WAV files to MP3 using 4 computer
systems. A total of 14 cores where available to PPSS to encode those files
using Lame. However, PPSS is not limited to encoding WAV files. To the
contrary, it is written to execute whatever command you want to execute. Gzip
a bunch of files in parallel? No problem. It is totally up to your
imagination.&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>Did you know that RDP is as insecure as telnet?</title><link href="https://louwrentius.com/did-you-know-that-rdp-is-as-insecure-as-telnet.html" rel="alternate"/><published>2008-11-21T09:47:00+01:00</published><updated>2008-11-21T09:47:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2008-11-21:/did-you-know-that-rdp-is-as-insecure-as-telnet.html</id><summary type="html">&lt;p&gt;Microsoft developed the remote desktop protocol in order to allow remote GUI-
based access to hosts. It is easy to pick on Microsoft and I do respect what
they have accomplished, however, it may not come as a surprise that they did
it all wrong with RDP in terms of …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Microsoft developed the remote desktop protocol in order to allow remote GUI-
based access to hosts. It is easy to pick on Microsoft and I do respect what
they have accomplished, however, it may not come as a surprise that they did
it all wrong with RDP in terms of security.&lt;/p&gt;
&lt;p&gt;By default, out-of-the-box, a server or desktop supports RDP with RC4
encryption. Most recent servers and clients support 128-bits encryption.
Sounds secure, right? Well, it isn't unfortunately. There are two major
security weaknesses that affect the remote desktop protocol.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Keystroke vulnerability&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The original , RDP version 4.0, is based on the T.128 protocol. Input events,
such as keystrokes, are sent to the server with a unique timestamp as
specified in the T.128 standard. This means that each message containing an
input event is unique and so will be the checksum generated from this input
event data. In other words: if two RDP messages contain the same data, they
will still be unique because of the timestamp. Microsoft did it right in RDP
version 4.0, but there was one drawback: the timestamp generated overhead,
making RDP messages relatively large.&lt;/p&gt;
&lt;p&gt;So in RDP version 5.0, Microsoft decided to drop the timestamp. Thus, if two
RDP messages contain the same data, their checksum will be identical. So if
the same key is pressed twice, the two packets that are generated will contain
different encrypted data segments but the checksums will be identical.
Although it is not clear which key is pressed, if a larger data set is
analyzed, patterns can be discovered and an accurate guess can be made to wich
keys are pressed.&lt;/p&gt;
&lt;p&gt;In a nuttshell an attacker that has access to the data stream of an RDP
session will be able to decode keystrokes and thus be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;obtain your username and password, allowing access to the system!&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;read what you type.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Please visit the following location as it provides a more detailed explanation
of this vulnerability:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.xatrix.org/article.php?s=1943"&gt;http://www.xatrix.org/article.php?s=1943&lt;/a&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Man-in-the-middle-attack&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;At first, back in 2003, RDP-clients did not verify the identity of the RDP
server. So an attacker can easily spoof an identity and perform a man-in-the-
middle-attack. Microsoft attempted to fix this vulnerability but did not
succeed. Although more recent RDP-clients do verify the identify of the
server, it is still possible to spoof this identity. Microsoft uses a fixed
hard-coded key to identify the server with. This key resided in a system DLL
that is available to the general public. An attacker can easily obtain this
key, create a fake identity and still prove to be legitimate since the
identity is signed with a trusted key.&lt;/p&gt;
&lt;p&gt;More detailed information:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.oxid.it/downloads/rdp-gbu.pdf"&gt;http://www.oxid.it/downloads/rdp-gbu.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Conclusion&lt;/p&gt;
&lt;p&gt;Given these vulnerabilities, RDP is, in its default configuration, virtually
as insecure as plain old telnet. Think about that the next time you logon with
administrator credentials using RDP.&lt;/p&gt;
&lt;p&gt;Tool that implements the attacks&lt;/p&gt;
&lt;p&gt;The well-known hack-tool Cain &amp;amp; Abel has a build-in RDP man-in-the-midlle
implementation. It automatically decrypts (parts of) RDP data packets and
reveals the key strokes that are send to a server. So if you don't believe
this story and just want to see for yourself how easy such an attack really
is, download this tool and test it for yourself.&lt;/p&gt;
&lt;p&gt;To defend against the attacks&lt;/p&gt;
&lt;p&gt;To protect against this attack, it is strongly advised to implement RDP based
on TLS/SSL encryption. Ofcourse, you'll have to install a server-side SSL-
certificate and it may be necessary to obtain an official (as in not self-)
signed certificate.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet2.microsoft.com/windowsserver/en/library/a92d8eb9-f53d-"&gt;http://technet2.microsoft.com/windowsserver/en/library/a92d8eb9-f53d-4e86-ac9b-29fd6146977b1033.mspx?mfr=true&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So please understand the risks of using RDP, especially over the Internet. If
TLS is for some reason not an option, use an encrypted VPN-connection to
tunnel the RDP-session in, as an added layer of protection. Never use RDP in
its default configuration over the interne without additional protection.&lt;/p&gt;
&lt;p&gt;EDIT: IN RDP version 6.0 the man-in-the-middle-attack is no longer possible!&lt;/p&gt;
&lt;p&gt;EDIT2: Configure your terminal server to use FIPS compliant encryption. It
will use Triple DES encryption even if TLS is not enabled.&lt;/p&gt;
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;After you enable this setting on a Windows Server 2003-based computer, the
following is true:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;The RDP channel is encrypted by using the 3DES algorithm in Cipher Block
Chaining (CBC) mode with a 168-bit key length.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The SHA-1 algorithm is used to create message digests.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Clients must use the RDP 5.2 client program or a later version to
connect.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So you don't need to use TLS if you want to use a more secure algorithm than
RC4.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;4e86-ac9b-29fd6146977b1033.mspx?mfr=true&lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry><entry><title>The kind of sound you never want to hear from your computer</title><link href="https://louwrentius.com/the-kind-of-sound-you-never-want-to-hear-from-your-computer.html" rel="alternate"/><published>2008-11-14T21:16:00+01:00</published><updated>2008-11-14T21:16:00+01:00</updated><author><name>Louwrentius</name></author><id>tag:louwrentius.com,2008-11-14:/the-kind-of-sound-you-never-want-to-hear-from-your-computer.html</id><content type="html">&lt;p&gt;&lt;a href="http://datacent.com/hard_drive_sounds.php"&gt;The sounds of hard drives that have perished&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;These sounds are only frightening or scary if you imagine your precious data
only exists on that failing drive. If you make consistent and frequent backups
and/or you run a fault-tolerant RAID flavour, it is but a nuisance. &lt;/p&gt;</content><category term="Uncategorized"/><category term="Uncategorized"/></entry></feed>